Skip to content
VPSDen
Reference · updated 2 July 2026

The Jurisdiction Matrix

Where your server physically sits determines what law reaches it. Not where the company is registered, not what the marketing page promises, not what the Terms of Service say. This is the comparison we wanted when we started and could not find anywhere.

It is free, it is not gated, and it includes the regions where we tell you outright not to host if your threat model is adversarial — including our own fastest and most profitable one.

Short answer

Which jurisdiction should I pick?

Iceland for the best overall balance — no retention mandate reaching hosting providers, outside the EU and the Fourteen Eyes, no DMCA, slow MLAT, and an estimated ~21 ms from London. Switzerland where dual-criminality protection matters. Seychelles for maximum legal distance — no bilateral MLAT with the United States — if you can absorb an estimated ~148 ms from London. Panama for the Americas; a US mutual legal assistance treaty has been in force there since the mid-1990s, and its row sets out what that does and does not reach. Romania for the best price-to-protection ratio inside the EU. Amsterdam only when raw performance outweighs jurisdiction — it is a Nine Eyes member with fast MLAT cooperation.
RegionData retention mandateEU14 EyesDMCAMLAT speedTakedown requiresPrice factor
🇮🇸Reykjavík
Iceland
No general retention mandate for hosting providersslowCourt order from an Icelandic court only×1.00
🇳🇱Amsterdam
Netherlands
Dutch retention Act suspended by court order (2015); no general mandate sinceyesmemberfastSubstantiated Art. 16 DSA report, or a Dutch court order×0.95
🇨🇭Zürich
Switzerland
BÜPF: full telecom retention duty does not apply; derived-service duties mayslowSwiss court order; dual-criminality required for MLAT×1.25
🇷🇴Bucharest
Romania
Struck down as unconstitutional (Decisions 1258/2009, 440/2014)yesmoderateSubstantiated Art. 16 DSA report, or a Romanian court order×0.90
🇧🇬Sofia
Bulgaria
Partially struck down (2015); narrow scope, telecom onlyyesmoderateSubstantiated Art. 16 DSA report, or a Bulgarian court order×0.88
🇲🇩Chișinău
Moldova
No general mandate applicable to hosting providersslowMoldovan court order only×1.05
🇵🇦Panama City
Panama
None applicable to hostingmoderatePanamanian court order; no notice-and-takedown route×1.20
🇸🇨Victoria
Seychelles
NoneslowSeychellois court order only; no bilateral MLAT with the US×1.35
🇲🇾Kuala Lumpur
Malaysia
No general mandate for hosting providersslows.43H owner notification (48-hour window), MCMC order, or court order×1.10
favourable to the customer unfavourableMLAT speed — how quickly a foreign legal assistance request becomes an enforceable local order
Analysis

What each region actually gives you

Our honest assessment, including where a region is the wrong choice.

🇮🇸Reykjavík, Iceland

outside 14 Eyesnon-EUslow MLAT
Detail

Nothing in Icelandic law obliges us to retain traffic or subscriber records for this region. A six-month duty does exist — Art. 89 of the Electronic Communications Act No. 70/2022 — and it is addressed to telecommunications undertakings; it has not been read to reach VPS hosting, and that boundary is the whole of what this region buys you on retention. Content comes down here on an order from an Icelandic court and on nothing else, because Iceland provides no administrative notice route a rights holder could use instead. Iceland is in the EEA and outside the EU, so the Digital Services Act does not apply.

🇳🇱Amsterdam, Netherlands

Fourteen Eyes memberEU / DSA applies
Detail

Fastest and cheapest region, but also the most legally exposed one we sell. EU jurisdiction, Nine Eyes member, and cooperative MLAT posture. Choose Amsterdam for performance, not for adversarial threat models.

🇨🇭Zürich, Switzerland

outside 14 Eyesnon-EUslow MLAT
Detail

Switzerland requires dual criminality for mutual legal assistance, and Swiss courts have historically been slow to grant foreign requests against hosting intermediaries. Do not read BÜPF as inapplicable: since the revision in force 1 March 2018 it distinguishes full telecommunications service providers, who carry retention and interception duties, from providers of derived communication services, a category the Federal Council reads as covering hosting and cloud. Derived-service providers have no general retention duty but must tolerate surveillance measures and surrender data they actually hold. Premium region — priced accordingly.

🇷🇴Bucharest, Romania

outside 14 EyesEU / DSA applies
Detail

Romania is in the EU but its Constitutional Court has twice invalidated blanket data-retention legislation, and the country is not part of the Five/Nine/Fourteen Eyes arrangements. Best price-to-protection ratio inside the EU.

🇧🇬Sofia, Bulgaria

outside 14 EyesEU / DSA applies
Detail

The cheapest way to buy an EU-located instance from us. Bulgaria is an EU member, so the DSA applies, but it is not part of the Eyes arrangements and enforcement bandwidth is limited.

🇲🇩Chișinău, Moldova

outside 14 Eyesnon-EUslow MLAT
Detail

Non-EU, non-Eyes. Foreign complainants must obtain a Moldovan court order, which in practice almost never happens for hosting disputes. Bandwidth is more expensive here than in the EU, hence the multiplier.

🇵🇦Panama City, Panama

outside 14 Eyesnon-EU
Detail

A US criminal investigation has a formal route into this region. Two instruments carry it: the Panama–United States mutual legal assistance treaty, in force since the mid-1990s; and the Council of Europe Convention on Cybercrime, which Panama acceded to in 2014 and whose Articles 29 to 31 cover expedited preservation of and access to stored computer data. Neither has direct effect on us. A request under either is executed under Panamanian law, and we produce nothing until a Panamanian court orders us to. The MLAT rating on this row is moderate for that reason: a bilateral treaty moves faster than the letters-rogatory route a country without one leaves a foreign prosecutor with. It is our own estimate and not a throughput measurement, because we hold no records that would support one — check both instruments against the treaty depositaries. Operationally: no retention duty reaches hosting here, there is no notice-and-takedown route for copyright, and London is an estimated ~122 ms away.

🇸🇨Victoria, Seychelles

outside 14 Eyesnon-EUslow MLAT
Detail

Our highest-isolation region. Seychelles has no data-retention regime and no bilateral mutual legal-assistance treaty with the United States. It is not a legal vacuum: the Mutual Assistance in Criminal Matters Act 1995 and Commonwealth (Harare Scheme) obligations both provide routes, and Seychelles is engaged with the Council of Europe Convention on Cybercrime, whose Articles 25 to 35 cover expedited preservation and access to stored data. Confirm the current accession status yourself rather than taking ours. Transit is satellite-and-subsea expensive, which is why the multiplier is 1.35.

🇲🇾Kuala Lumpur, Malaysia

outside 14 Eyesnon-EUslow MLAT
Detail

Best APAC option for customers who want distance from both EU and US process — but it is the one region of ours with a statutory notice-and-takedown route, and you should not choose it to avoid one. Sections 43B to 43I of the Copyright Act 1987, inserted by the Copyright (Amendment) Act 2012, give a copyright owner a direct notification route under s.43H with a fixed 48-hour removal window, subject to counter-notification under s.43I. Malaysia also has an active telecom regulator (MCMC) with local content powers, relevant mainly for content aimed at Malaysian audiences.

How to read this table

Four columns carry almost all of the weight, and they are not equally important. In our experience of 12 years of legal correspondence, they rank like this:

  1. Data retention mandate. This is the one that actually bites. If the law requires your provider to keep connection records, its no-logs policy is not a policy — it is a crime it has chosen not to commit yet. Every region we sell has either no mandate reaching hosting providers, or one that has been struck down by a constitutional court.
  2. Takedown regime. Determines whether a notice can remove your content or whether somebody has to hire local counsel and win in court. The gap between those two is roughly a factor of a thousand in cost and six months in time. Read this column region by region rather than as a rule: Malaysia is the one region of ours with a statutory notice route, under s.43H of its Copyright Act 1987, and it carries a 48-hour removal window.
  3. MLAT responsiveness. Determines how quickly a foreign investigation becomes a binding local order. Dual-criminality requirements — Switzerland's in particular — defeat entire categories of request outright.
  4. Fourteen Eyes membership. Matters for adversarial threat models. For most workloads it is a theoretical concern, and treating it as the single deciding factor leads people to reject good jurisdictions for bad reasons.

Sources and method

Every row states the instrument it rests on, and we cite the instrument rather than the commentary about it: Art. 89 of the Icelandic Electronic Communications Act No. 70/2022, which fixes the six-month duty and the class of undertaking it is addressed to; Romanian Constitutional Court decisions 1258/2009 and 440/2014; the 11 March 2015 District Court of The Hague interim-relief judgment suspending the Dutch Telecommunications Data Retention Act for conflict with Articles 7 and 8 of the Charter (a suspension, not an annulment — Article 120 of the Dutch Constitution bars a court from reviewing an Act of Parliament); Articles 16 and 17 of Regulation (EU) 2022/2065; 17 U.S.C. § 512; ss.43B–43I of the Malaysian Copyright Act 1987 as inserted by the Copyright (Amendment) Act 2012; the revised Swiss BÜPF in force 1 March 2018, including its category of derived communication service providers; and, for Panama, the mutual legal assistance treaty with the United States, in force since the mid-1990s, together with Panama's 2014 accession to the Council of Europe Convention on Cybercrime. MLAT responsiveness is our own assessment based on 12 years of handling legal correspondence and on published processing-time data — including the roughly ten-month average for requests submitted to the United States reported by the President's Review Group in 2013.

This is a description of how the law applies to hosting operations. It is not legal advice, and if your situation is genuinely contested you should retain counsel in the relevant jurisdiction. We review this page quarterly and welcome corrections; corrections we accept are published with attribution.

Reuse

This table is published under CC BY 4.0. Copy it, cite it, put it in your own comparison — a link back is appreciated but not required. We would rather the information was widely available than exclusively ours.

Questions

Jurisdiction questions

Which jurisdiction is best for offshore hosting?

Iceland offers the strongest overall balance: no data-retention mandate reaches hosting providers — the six-month duty in its Electronic Communications Act binds telecommunications undertakings — it sits outside both the EU and the Fourteen Eyes arrangements, the DMCA has no force there, mutual legal assistance is slow, and it is still an estimated ~21 ms from London. Switzerland is the strongest choice where dual-criminality protection matters. Seychelles offers the greatest legal distance — it has no bilateral mutual legal assistance treaty with the United States — at a cost of an estimated ~148 ms from London. Panama is outside the EU and outside the Eyes arrangements and gives the best Americas latency we sell; a US mutual legal assistance treaty has been in force there since the mid-1990s and Panama acceded to the Budapest Convention on Cybercrime in 2014, so US criminal process has a route into the region, executed under Panamanian law by a Panamanian court. Romania gives the best price-to-protection ratio inside the EU.

Does the DMCA apply to servers outside the United States?

No. The DMCA is 17 U.S.C. § 512, a United States statute, and it contains no extraterritoriality provision. A hosting provider with no US entity, no US infrastructure and no US banking relationship has no safe harbour to lose and therefore no statutory obligation to act on a notice. What applies instead is the copyright law of the country where the hardware physically sits.

Is a Netherlands server private?

It is legally exposed relative to our other regions. The Netherlands is a Nine Eyes member with a cooperative mutual legal assistance posture and it falls under the EU Digital Services Act. It also has genuinely strong domestic privacy jurisprudence, and its retention Act was suspended by the District Court of The Hague in interim-relief proceedings on 11 March 2015 for conflict with Articles 7 and 8 of the Charter, with no general mandate enacted since. It is an excellent region for performance and a poor one for an adversarial threat model.

What does Fourteen Eyes membership mean for a hosted server?

It means signals intelligence collected on infrastructure inside that country can be shared with the other member states through a channel that is not visible to you, not reviewable by your local courts, and not reflected in any transparency report. It is a meaningful factor for adversarial threat models and largely theoretical for ordinary ones. It is not a law-enforcement mechanism — a prosecutor seeking evidence uses an MLAT or a domestic warrant instead.

Now pick the one that matches your threat model.

Change region in the configurator and the price updates instantly. Nine countries, nine legal regimes, one checkout.

No email · No KYC · Pay in Monero · Deployed in under a minute