All systems operational Your IP: 216.73.216.190 info@cloudhosting.lv +371 66 66 29 69 Client area

← All questions

What is GDPR and what does it actually require?

GDPR is Regulation (EU) 2016/679, the EU law governing how organisations handle information about people since 25 May 2018. It forces you to know what personal data you hold, why you may hold it, who else touches it and when it is deleted, and to prove that on request. The binding text is the regulation itself and real edge cases are a lawyer's call; what follows is the working version that comes up in meetings.

Where it applies, and what counts as personal data

The regulation binds every member state directly but leaves room for national rules in about fifty places, which is why Latvia has its own layer in the Fizisko personu datu apstrades likums and why some details differ between countries. It applies if you are established in the EU, wherever your servers sit, and to companies outside the EU that sell to or track people here. B2B is not exempt: a named work email and a direct mobile number belong to a person.

Personal data is any information relating to an identified or identifiable person: IP addresses in your logs, cookie identifiers, an employee's phone number, a photograph of a face, a CV, camera footage. Pseudonymised data, where the name is swapped for a reversible ID, still counts. Article 9 adds stricter rules for health, biometrics, religion and ethnic origin. Most small companies are sure they hold none of that, then remember the sick notes in HR.

You are the controller, your host is the processor

The controller decides why and how data is processed; the processor only acts on instructions. Your hosting provider, payroll bureau and CRM vendor are processors. You are the controller, and the regulator and the individual come to you first. Processors carry direct duties too and can be fined themselves.

DecisionWho makes it
Why the data is collectedYou, the controller
Physical and network securityThe provider
Answering an access requestYou, with the provider's help
Whether a breach is notifiableYou

Six lawful bases, and why consent is the wrong default

Every activity needs one of six bases from Article 6, picked before you start and named in your privacy notice. You cannot switch quietly when the first one fails.

BasisTypical useThe catch
ConsentNewsletters, non-essential cookiesUnbundled, and as easy to withdraw as to give
ContractDelivering what the customer orderedNot the marketing around it
Legal obligationInvoices, tax, employment recordsNeeds a law, not a habit
Vital interestsLife and deathAlmost never in business
Public taskPublic bodiesNot for ordinary companies
Legitimate interestsFraud prevention, network security, operationsRequires a documented balancing test

Consent is the weakest of the six and the most abused. It can be withdrawn at any moment, taking the ground from under whatever you built on it, and between employer and employee the imbalance makes it hard to call free. Most of what companies collect consent for is really contract or legitimate interests. The cookie banner is a separate ePrivacy duty either way.

The rights people use, and the one month clock

People can ask for a copy of their data, correction, erasure, restriction and portability, and they can object. Objection to direct marketing is absolute; erasure is not, because data you must keep by law stays. You have one month, extendable by two more for a complex request if you say so inside the first month. Realistically it arrives from a former employee or a customer in a dispute and spans mailboxes, the CRM and backups at once. Nobody meets that deadline by improvising, which is why Article 30 asks for a record of your processing.

Article 28 and the data processing agreement

Whenever a processor touches personal data for you there must be a written contract, and Article 28 sets its contents: subject matter, duration, purpose, type of data and categories of people, plus mandatory clauses. Processing only on your documented instructions, confidentiality for staff, security measures, no sub-processor without your authorisation and on the same terms, help with data subject requests and breaches, deletion or return at the end, and audit rights for you.

"We host in the EU" is not a substitute. Location answers the transfer question and says nothing about instructions, sub-processors or deletion. A bank or an auditor wants the signed agreement and the sub-processor list, including backup and filtering vendors. Our data protection page sets out what we sign.

72 hours, and who has to be told

A breach goes to the supervisory authority without undue delay and, where feasible, within 72 hours of you becoming aware, unless it is unlikely to pose a risk to people. In Latvia that is Datu valsts inspekcija. The clock starts at reasonable certainty that something happened, not when the investigation ends. Where the risk is high you must tell the individuals too, unless strong encryption left the data unreadable.

A breach is not only a hacker: ransomware, a lost laptop, an email to the wrong recipient, a misconfigured bucket and permanent data loss all count. Your processor must tell you quickly but does not file with the regulator for you. Under NIS2, reporting runs on a separate and faster clock.

Transfers outside the EU after Schrems II

Sending data outside the EU, or letting someone outside look at it remotely, is a transfer and needs its own footing: an adequacy decision, standard contractual clauses or binding corporate rules. Schrems II struck down the Privacy Shield in 2020 and made the clauses conditional on assessing the destination country's surveillance law. The 2023 EU and US framework restored a route for certified American organisations, but it is being litigated and may not be the last word. Which is the honest argument for keeping data here: nothing to assess, nothing to redo when an instrument falls. That is why clients ask for a data centre in Riga rather than a cheaper region elsewhere.

Retention, the rule everyone ignores

Data may be kept only as long as the purpose needs it, yet in most companies the real retention period is forever: CVs from a hiring round years ago, a list built at a trade fair nobody remembers, backups holding people you deleted from production.

Good practice is a short schedule, category by category, with a legal reference where one exists. Latvian accounting rules require source documents for at least five years, so invoices are easy. Personnel and payroll records carry much longer archive obligations. Marketing data has no statutory period, so you set one and justify it. Regulators accept that you cannot cut one person out of an immutable backup set, provided your erasure procedure says so and a restore does not resurrect them.

Fines, and the risk that is actually likely

Two ceilings: up to 10 million euro or 2 percent of worldwide annual turnover, whichever is higher, for records, security and processor contracts, and up to 20 million or 4 percent for the principles, lawful basis, rights and transfers. Those numbers describe a hotel chain or a social network. For a normal company the sequence is different: an ex-employee or an annoyed customer complains, Datu valsts inspekcija writes with questions and a deadline, and you spend three weeks assembling documents you should have had. Individuals can also sue for compensation, and usually the commercial version bites first: a tender sends a data protection annex you cannot answer.

What a hosting provider can and cannot take off your plate

A provider can run the building and the network, control physical access, keep your data in one jurisdiction, sign the Article 28 agreement, name its sub-processors, tell you fast when something happens on its side, and supply the infrastructure controls: isolation, backups, filtering at the edge.

It cannot choose your lawful basis, write your privacy notice, keep your record of processing, set retention periods, find personal data inside your application, act as your data protection officer, or make a badly built system compliant. If your code writes card numbers into a log file, the data centre around it is irrelevant.

Where we fit is the narrow part: our own data centre in Riga on our own network, data staying in the EU under EU law, engineers reachable around the clock, and a data processing agreement we will sign. Everything above that line stays yours, and it pays to write that boundary down before an auditor asks.

Rather have us run it for you?
Single-domain certificate. One hostname, one trusted certificate.
Learn more

Ready to start?

Deploy in minutes or talk to an engineer about what fits your project.