Privacy Guide
Data Retention Laws by Country: What Your Host Can Legall...
Privacy Guide

Data Retention Laws by Country: What Your Host Can Legally Keep

AnubizHost Team

Every privacy-hosting provider claims 'no logs.' Almost none of them explain the difference between a company policy and a legal mandate. A host can promise not to log anything and still be required by local law to retain certain records - and if that happens, the promise was never really theirs to make. Here is how to tell the difference before you trust a claim.

Company Policy vs Legal Mandate: Two Different Things

A hosting company can promise not to keep connection logs, billing metadata, or IP history beyond what is operationally necessary. That is a company policy, and it is only as durable as the company's willingness and legal ability to keep it. If the jurisdiction the company operates in has a binding data-retention statute, the policy is overridden by law regardless of what the marketing page says. Evaluating any 'no logs' claim means asking which of the two you are actually being promised.

This is not a hypothetical distinction. A VPN or hosting provider can be entirely sincere in its "no logs" marketing and still be legally compelled to start logging going forward under a valid court order or a binding national security directive, sometimes without being permitted to disclose that the order exists at all. A policy is a statement of intent under normal conditions; it is not a guarantee against a country's own legal system acting on the company directly.

The EU Data Retention Landscape

The EU's original 2006 Data Retention Directive, which mandated blanket retention of telecommunications metadata across member states, was struck down by the Court of Justice of the European Union in the 2014 Digital Rights Ireland ruling as incompatible with fundamental privacy rights. Since then, there is no single EU-wide mandate - individual member states have adopted their own national rules, ranging from strict to minimal, which is one reason the specific EU country a data center operates in matters as much as EU membership itself.

This is a useful corrective to the common assumption that "EU hosting" is a single, uniform privacy standard. It is not. Two EU member states can have meaningfully different retention obligations on their hosting and telecommunications companies, which is exactly why a claim like "DMCA-ignored, EU jurisdiction" needs to specify the actual country, not just the trading bloc, to mean anything concrete.

Why Jurisdiction Choice Is Part of a Retention Strategy

AnubizHost's offshore jurisdictions - Romania, Ukraine, Iceland, Netherlands - were selected partly on this basis: data centers in these locations are not bound by the kind of blanket retention mandate that some Western European and North American jurisdictions maintain, and our own operating policy is to retain the minimum required for billing and abuse response, nothing more.

Note: no host, including AnubizHost, can promise total legal immunity from every possible future retention requirement in every jurisdiction. What matters is choosing a jurisdiction with a track record of minimal mandates and a company whose stated policy matches that legal reality rather than overstating it.

Beyond Europe: A Broader Pattern Worth Knowing

The EU is not unique in having walked back a blanket retention mandate under legal challenge - it is simply the most documented example. The general pattern repeats globally: sweeping mandatory-retention laws get proposed after a security incident, get challenged in court on privacy grounds, and frequently get narrowed or struck down over the following years. What this means practically is that a jurisdiction's retention posture is not static. It is worth periodically re-checking a host's stated policy against current law rather than assuming a claim made years ago still holds.

Questions to Ask Any Host About Retention

What does your country's law specifically require you to retain, for how long, and under what legal process can that data be requested. Does your stated 'no logs' policy apply to connection metadata, billing information, or both. Is the answer written down publicly, or only offered as a verbal reassurance. A host willing to answer these specifically is worth more trust than one that only offers a generic privacy pledge.

See AnubizHost's current offshore jurisdictions to compare retention posture and DMCA policy by location.

Frequently Asked Questions

Does AnubizHost keep connection logs?

AnubizHost's policy is to retain the minimum information required for billing and abuse response across every jurisdiction we operate in, and no jurisdiction we use maintains a blanket telecommunications retention mandate of the kind struck down under Digital Rights Ireland.

What was the Digital Rights Ireland case?

A 2014 ruling by the Court of Justice of the European Union that struck down the EU's 2006 Data Retention Directive, finding its blanket metadata-retention mandate incompatible with fundamental privacy rights under EU law. It remains the reason there is no single EU-wide retention mandate today.

Get your Offshore VPS

No KYC. Crypto accepted. Romania + Iceland jurisdictions. Entry from $19.99/mo.

See Plans

Anubiz Chat AI

Online
Data Retention Laws by Country: What Your Host Can Legally Keep | AnubizHost