Skip to content
VPSDen
Legal8 min read1,103 words

What "DMCA-ignored hosting" actually means

Why 17 U.S.C. § 512 binds no provider without a US nexus, what that does and does not buy you, and what actually removes content from an offshore server.

Short answer

Is DMCA-ignored hosting real or is it marketing?

It is real but the name is misleading. The DMCA is 17 U.S.C. § 512, a United States statute that conditions an intermediary safe harbour on removing content after a compliant notice. A provider with no US entity, no US infrastructure and no US banking relationship has no safe harbour to lose, so § 512 creates no obligation for it at all. What applies instead is the copyright law of the country where the hardware sits: in Iceland, Panama, Seychelles, Switzerland and Moldova a claimant has to obtain a local court order, which is expensive and slow and therefore rare. Malaysia is the exception — its Copyright Act 1987 has carried a statutory notice-and-takedown route with a 48-hour removal window since the 2012 amendment. A valid local order still binds the provider everywhere, and criminal content is handled by a separate and much faster process than an infringement claim.

"DMCA-ignored" is one of the most-searched phrases in offshore hosting and one of the most misunderstood. It sounds like a service where laws are disregarded. It is not. It describes an ordinary jurisdictional fact, dressed up as a feature.

What the DMCA actually is

The Digital Millennium Copyright Act of 1998 added § 512 to Title 17 of the United States Code. The relevant part creates a safe harbour: an online service provider is shielded from monetary liability for infringement carried out by its users, provided it meets conditions including expeditious removal of material on receipt of a compliant notice, designation of an agent with the Copyright Office, and a repeat-infringer policy.

Two things follow that people consistently miss. The DMCA does not order anyone to remove anything — it offers a liability shield in exchange for compliance. And that shield is only worth something to a provider who is exposed to US copyright liability in the first place.

Why it does not reach foreign servers

US statutes are presumed not to apply extraterritorially unless Congress says otherwise, a principle the Supreme Court restated forcefully in Morrison v. National Australia Bank (2010) and again in RJR Nabisco v. European Community (2016). Section 512 contains no extraterritoriality provision.

So for a hosting provider with:

  • no US-incorporated entity,
  • no servers, staff or offices in the United States,
  • no US bank account or payment processor,
  • no assets a US judgment could be enforced against,

a § 512 notice has no more legal force than a strongly worded letter. There is no safe harbour to lose and no jurisdiction to be sued in. That is what "DMCA-ignored" means, and it is not a policy choice by the provider — it is the structure of the statute.

The caveat that matters: this depends on the provider genuinely having no US nexus. A company with a Delaware entity, or a US payment processor, or servers in a US facility, absolutely does have exposure, whatever its marketing page says. Ask specifically.

What applies instead

Copyright is territorial, so what applies is the law of the country where the hardware sits, plus the Berne Convention floor that almost every country implements. In practice:

Court-order jurisdictions

Iceland, Switzerland, Panama, Seychelles and Moldova have no administrative notice-and-takedown regime for copyright. A rights holder who wants content removed must retain local counsel, establish jurisdiction, file, and obtain an order. That routinely costs five figures and takes months, which is why it essentially never happens over a single VPS.

Malaysia: statutory notice-and-takedown

Malaysia belongs in a category of its own and is frequently misfiled. Sections 43B to 43I of the Copyright Act 1987, inserted by the Copyright (Amendment) Act 2012, give a copyright owner a direct notification route to the service provider under section 43H, with a hard 48-hour removal window as the price of the safe harbour, and a counter-notification route for the subscriber under section 43I. That is a real administrative takedown regime, and on the deadline it is tighter than the DMCA. Choose Kuala Lumpur for regional latency, not for copyright distance.

EU jurisdictions

Our Amsterdam, Bucharest and Sofia regions sit inside the European Union, where Regulation (EU) 2022/2065 applies. Article 16 obliges the provider to run a reporting channel and to deal with what arrives; Article 16(2) fixes what a report must contain before it counts, and a bare allegation that a work is infringing does not clear it. There is no removal-on-assertion and no counter-notice clock, but there is a real duty on real timescales. If that exposure matters to you, buy outside the EU.

What still gets content taken down

Jurisdiction shopping addresses copyright. It does not address:

  • Criminal content. CSAM is illegal in every country we operate in, and the response is immediate, coordinated and does not involve a leisurely court process. No provider anywhere will resist this, including us.
  • Upstream pressure. Your provider has transit carriers, and those carriers have their own acceptable-use policies. A provider that does not own its IP space and does not have diverse transit can lose connectivity to a complaint that never reaches a court. Ask who the upstreams are.
  • Domain seizure. Your server may be in Panama while your .com is administered by a US registry that will act on a US court order. Match the TLD to the threat model: .is, .ch and .li are administered outside US reach.
  • Payment strangulation. The historically most effective tactic against a site is not removal but demonetisation. It is one reason crypto-only providers are structurally more resilient.
  • Local orders. A binding order from a court in the country where the server sits is binding, and we comply with it. That is the deal.

Red flags in "DMCA-ignored" marketing

  • "Bulletproof, anything allowed." No legitimate provider allows anything. A host with no acceptable-use policy at all is a host that will lose its transit and disappear with your data — the risk is to you.
  • A US or German datacentre on the network page. Both are jurisdictions where a notice alone can produce a removal. Check where the hardware is, not where the company is registered.
  • Card payments accepted. Card acceptance implies an acquiring bank, which implies a jurisdiction with financial regulators and a chargeback process. It is a strong hint that the provider's independence is more limited than advertised.
  • No published legal contact. A provider that will not say how it handles legal process has not thought about how it handles legal process.
  • Anonymous operators with no operating history. Exit scams in this market are common. Look for years of continuous operation and a verifiable public record.

Our position

We operate no infrastructure in the United States and hold no US corporate presence, so § 512 does not apply to us. When we receive a copyright complaint we forward it to the customer for information and take no action on it. We act on a copyright matter only when presented with a binding order from a court in the country where the relevant hardware sits.

We do maintain a narrow acceptable-use policy covering child sexual abuse material, malware command-and-control, bulk unsolicited email, and attacks launched from our network against third parties. Those are the categories that get transit revoked and hardware seized — enforcing them is what keeps the service alive for everyone else. Everything outside that list is between you and the law of the jurisdiction you chose.


This is a description of how the law applies to our operations. It is not legal advice, and if your situation is genuinely contested you should retain counsel in the relevant jurisdiction.

Cite this page

VPSDEN, “What "DMCA-ignored hosting" actually means”, vpsden.com/kb/dmca-ignored-hosting-explained, revised 2026-04-11. Published under CC BY 4.0 — reproduce it freely, with attribution.

Found an error? We amend the article and name the reader who reported it. Tell us.

Offshore VPS from €4.40/month. No KYC, no email, paid in Monero.

Nine jurisdictions, RAM-only options, disks we cannot read, live in about 48 seconds.

No email · No KYC · Pay in Monero · Deployed in under a minute