Skip to content
VPSDen
Legal14 min read2,462 words

How to choose an offshore hosting jurisdiction (2026)

How to pick a hosting country: data-retention law, intelligence-sharing membership, takedown regimes, MLAT speed, and the trade-off against latency.

Short answer

Which country should I host my offshore VPS in?

For most people the answer is Iceland: no data-retention mandate applies to hosting providers, it is outside the EU and outside the Fourteen Eyes arrangements, the DMCA has no force there, and it is still an estimated ~21 ms from London. Choose Switzerland if you want dual-criminality protection against foreign legal assistance requests, Romania if you want EU network quality at Balkan prices with a Constitutional Court that has twice struck down data retention, and Seychelles if maximum legal distance matters more than the latency it costs you — an estimated ~148 ms from London — because it is the one region we sell with no bilateral mutual legal assistance treaty with the United States. Panama gives the best Americas latency we sell and has no notice-and-takedown route for copyright; a US mutual legal assistance treaty has been in force there since the mid-1990s and Panama acceded to the Budapest Convention on Cybercrime in 2014, so US criminal process has a route into the region, executed under Panamanian law by a Panamanian court. Avoid hosting adversarial workloads in the Netherlands, Germany, the UK, France or the United States regardless of what the provider promises, because the legal exposure is a property of the country and not of the company.

"Offshore" is not a legal category. It is a marketing word that means "somewhere other than where you live," and on its own it guarantees nothing. A server in a country with mandatory data retention and a cooperative mutual legal assistance posture is offshore, and it is also worse than a server in your own bedroom, because you have added a company that can be leaned on without adding any protection.

What actually determines whether a jurisdiction protects you is a small set of concrete legal facts. This guide covers them, applies them to the nine countries we operate in, and tells you where we are the wrong answer.

The four questions that actually matter

Ignore the flags on the map. For any candidate country, get answers to these four:

  1. Is there a data-retention mandate that reaches hosting providers? If the law requires your host to keep connection records for twelve months, the host's no-logs policy is not a policy — it is a crime they have chosen not to commit yet.
  2. Is the country inside an intelligence-sharing arrangement? Fourteen Eyes membership means signals intelligence collected there is shareable with the other members by default, without a further legal process visible to you.
  3. What does it take to compel a takedown? A US-style notice-and-takedown regime means an email from a claimant can remove your content. A court-order-only regime means somebody has to hire a local lawyer, file, and win.
  4. How responsive is the country to foreign legal assistance requests? A slow, dual-criminality-requiring MLAT process converts a foreign investigation into an eighteen-month diplomatic exercise. A fast one converts it into a two-week formality.

Everything else — the provider's marketing, its "military-grade encryption," its Terms of Service — sits downstream of those four answers.

Data retention: who is required to keep what

There is no EU-level retention duty for a provider to inherit. Directive 2006/24/EC, which had required member states to impose blanket retention of telecommunications metadata, was invalidated by the Court of Justice in 2014, and the Court has since held that general and indiscriminate retention is incompatible with EU law even where a member state enacts it on its own account. Everything that binds a provider today is national law, and member states diverged sharply.

Region by region:

  • Romania struck its retention law down twice — Constitutional Court Decision 1258/2009, and again Decision 440/2014 after parliament tried to re-enact it. There is currently no general retention obligation.
  • The Netherlands had the Wet bewaarplicht telecommunicatiegegevens suspended by the District Court of The Hague on 11 March 2015, in interim-relief proceedings, for conflict with Articles 7 and 8 of the Charter. Note the procedural posture: a Dutch district court cannot annul a statute — Article 120 of the Constitution bars constitutional review of Acts of Parliament — so what happened was disapplication, not annulment. The practical result is the same: no general mandate has replaced it.
  • Bulgaria narrowed its regime substantially after a 2015 constitutional challenge; what survives applies to telecommunications operators, not to hosting.
  • Germany and France have both repeatedly attempted to re-legislate retention in forms designed to survive CJEU review. Treat both as jurisdictions where the question is open and the direction of travel is unfavourable.

Outside the EU the picture is simpler but not as clean as it is usually sold. Iceland, Moldova, Panama, Seychelles and Malaysia impose no general retention duty on hosting providers. Iceland is worth stating precisely: a six-month retention obligation does exist under its Electronic Communications Act, but it binds telecommunications undertakings and has not been read to reach VPS hosting.

Switzerland needs its own paragraph. The revised BÜPF, in force since 1 March 2018, does not simply exclude hosting. It distinguishes full telecommunications service providers (FDA), who carry retention and interception duties, from providers of derived communication services — a category the Federal Council's own explanatory material reads as covering hosting of email, chat, document-exchange and cloud services. Derived-service providers have no general retention duty, but they must tolerate surveillance measures and hand over data they actually hold. The Proton line of decisions before the Federal Administrative Court in 2021 confirmed that reduced-duty classification; it did not put such providers outside the Act, and anyone citing it for that proposition is citing it wrongly. The revision of the implementing ordinance (VÜPF) is a live risk to watch. The protection Zürich buys you is that we hold almost nothing to surrender — not that Swiss law cannot reach us.

One critical distinction that trips people up: a retention mandate compels the provider to keep records. It says nothing about what the provider chooses to collect in the absence of a mandate. A host in a no-retention country that voluntarily keeps 90 days of connection logs is offering you nothing.

Five, Nine and Fourteen Eyes

The arrangement is real, and the way it is discussed online is usually wrong. It is a signals-intelligence sharing framework, descended from the 1946 UKUSA Agreement. It is not a law-enforcement mechanism and it does not, by itself, mean a police force in one member country can read data in another.

The tiers:

  • Five Eyes — United States, United Kingdom, Canada, Australia, New Zealand.
  • Nine Eyes — adds Denmark, France, the Netherlands, Norway.
  • Fourteen Eyes (formally SIGINT Seniors Europe) — adds Belgium, Germany, Italy, Spain, Sweden.

Why it matters for hosting: intelligence collected on infrastructure inside a member state can be shared with the other members through a channel that is not visible to you, not subject to your local courts, and not covered by any transparency report your provider publishes. It is a reason to avoid those countries for adversarial threat models. It is not a reason to believe that a Dutch server is being actively read — the Netherlands is a Nine Eyes member and also has genuinely strong domestic privacy jurisprudence.

Of our nine regions, exactly one is a Fourteen Eyes member: the Netherlands. We sell it anyway, because it is our fastest and cheapest region and most workloads are not adversarial. We just say so on the product page instead of hoping you do not look it up.

Takedown regimes: DMCA, DSA and court orders

Three distinct regimes exist and they are routinely conflated.

The DMCA (United States)

17 U.S.C. § 512 creates a safe harbour for intermediaries conditional on expeditious removal upon receipt of a compliant notice. It also contains no extraterritoriality provision, so it does not attach to hosting infrastructure outside the United States. A server in Reykjavík is not subject to it. A provider with no US entity, no US infrastructure and no US bank account has no safe harbour to lose and therefore no statutory incentive to act on a notice.

This is what "DMCA-ignored hosting" actually means, and the phrase is misleading. Nothing is being ignored; the statute simply does not apply. What a provider outside the US is obliged to do about copyright is determined by its own country's copyright law, which almost always requires a court to be involved.

The DSA (European Union)

Regulation (EU) 2022/2065 applies to every hosting provider offering services in the EU, wherever the provider itself is established. Article 16 obliges the provider to run a channel for reporting allegedly illegal content and sets, at Article 16(2), the four things a report must carry before it counts; Article 17 requires a statement of reasons whenever the provider acts; Articles 11 and 12 require a designated point of contact. It is materially lighter-touch than the DMCA — nothing in it requires removal on mere assertion — but it is a real obligation and it reaches our Amsterdam, Bucharest and Sofia regions.

Court-order-only regimes

Iceland, Switzerland, Moldova, Panama and Seychelles all require a claimant to obtain an order from a local court. In practice this means hiring local counsel, establishing jurisdiction, and litigating — a process that costs five figures and takes months, which is why it almost never happens for hosting disputes.

Malaysia is not in that group

Malaysia is routinely listed as court-order-only, including by us until we checked. It is not. Sections 43B to 43I of the Copyright Act 1987, inserted by the Copyright (Amendment) Act 2012, create an ISP safe harbour with a notification procedure attached: under section 43H a copyright owner notifies the service provider directly, and the provider must remove or disable access within 48 hours of receipt to keep the safe harbour. Section 43I gives the subscriber a counter-notification and restoration route. A fixed 48-hour clock is in one respect stricter than 17 U.S.C. § 512, which only requires "expeditious" removal. If your reason for choosing a region is avoiding administrative takedown, Kuala Lumpur is the wrong region.

MLAT: how fast a foreign request becomes a local one

Mutual Legal Assistance Treaties are the mechanism by which a prosecutor in country A gets evidence held in country B. The variable that matters is not whether a treaty exists — most countries have some framework — but three things about it:

  • Dual criminality. Does the conduct have to be a crime in the requested country too? Switzerland requires this, which defeats a large class of requests outright.
  • Judicial review. Does a local judge examine the request, or does an executive ministry rubber-stamp it?
  • Throughput. MLAT requests submitted to the United States have historically averaged around ten months to complete — the figure comes from the 2013 Report of the President's Review Group on Intelligence and Communications Technologies, and it measures the DOJ Office of International Affairs acting as the receiving central authority, not US prosecutors waiting on foreign evidence. Read it as a proxy for how slowly the machinery moves in either direction rather than as a number about outbound US requests. We do not publish throughput figures for our own regions, because we do not have records that would support them.

Whether a treaty exists at all is usually the least interesting of the three, and two of our regions are the exception. Seychelles holds no bilateral mutual legal assistance treaty with the United States. Panama has held one since the mid-1990s and has been a party to the Council of Europe Convention on Cybercrime since 2014, whose Articles 29 to 31 cover expedited preservation of and access to stored computer data. Read the instruments in force for the country you are considering.

A slow MLAT process is one of the strongest protections available, and it is entirely invisible on a provider's feature list.

Country by country

Our assessment of the nine regions we operate, ordered by overall protection rather than by price:

CountryRetention14 EyesDMCAMLATBest for
SeychellesNoneNoNoVery slow; no US treatyMaximum legal distance
IcelandNone applicableNoNoSlowBest overall balance
SwitzerlandTelecom onlyNoNoSlow, dual criminalityFinancial and legal work
MoldovaNone applicableNoNoSlowNon-EU, close to EU
PanamaNoneNoNoModerate; US treaty in force since the mid-1990s, Budapest Convention since 2014Americas latency, no notice-and-takedown
MalaysiaNone applicableNoNo (but s.43H notice-and-takedown applies)SlowAPAC audiences
RomaniaStruck down twiceNoNoModerateEU quality, low price
BulgariaNarrow, telecomNoNoModerateCheapest EU option
NetherlandsAnnulled 2015YesNoFastPerformance, not privacy

Iceland is the default recommendation and it is not close. It clears every one of the four questions, expression is protected at constitutional level by Article 73 of the Icelandic Constitution, and it costs you an estimated ~21 ms from London — a latency penalty most workloads cannot perceive.

One correction while we are here, because the search results carry it in the other direction: the Icelandic Modern Media Initiative does not protect a server in Reykjavík. IMMI is a policy programme the Althingi voted through in June 2010. It bound the ministries to draft; it created no rights on its own. Some of that drafting was enacted and some was not, so check which enacted provision you are relying on. The retention position above is the one that does the work.

The latency trade-off, quantified

Legal distance and network distance are correlated, and the correlation is the whole difficulty. Round-trip times to London from each of our nine regions, estimated from cable and peering geography rather than measured, so read them as orders of magnitude:

RegionTo London
Amsterdam~7 ms
Zürich~19 ms
Reykjavík~21 ms
Bucharest~40 ms
Sofia~45 ms
Chișinău~52 ms
Panama City~122 ms
Victoria~148 ms
Kuala Lumpur~168 ms

London is the reference point we hold a figure for in every region, so it is the only column here. The other reference points we carry differ by region and are listed on each location page.

Two practical notes. First, Reykjavík is unusually well placed for transatlantic work: Reykjavík is closer to New York than Frankfurt is, and the reason is Greenland Connect — the cable that leaves Iceland westward for Greenland and carries on to Newfoundland, instead of doubling back through mainland Europe first. Second, for anything that is not interactive — batch processing, storage, a mail server, a Tor relay — a couple of hundred milliseconds is irrelevant, and you should simply take the strongest jurisdiction available.

Four mistakes people make

1. Confusing the company's jurisdiction with the server's

These are different and both matter. A Seychelles-registered company operating a server in Frankfurt gives you a German server. German police do not need to care where the paperwork was filed. Ask specifically where the hardware sits, and prefer providers who tell you which facility.

2. Assuming "offshore" means "immune"

No jurisdiction is immune. Every country we operate in will act on a valid domestic court order, and so will we. The point of jurisdiction selection is to make obtaining that order slow, expensive and subject to a judge who is not the complainant's compatriot — not to reach a place where law stops.

3. Ignoring the upstream

A server in a perfect jurisdiction, on transit from a carrier that terminates service on receipt of an abuse email, is not protected. Ask who the provider's upstreams are and whether they own their IP space. We publish ours per region.

4. Optimising jurisdiction while leaking everything else

Jurisdiction is the outermost layer. It does nothing if you pay with a card in your own name, log in from your home IP without a tunnel, register a domain with real WHOIS data, or run an application that phones home with an identifier. Get the boring layers right first — they are where almost every real deanonymisation happens.


This article is updated quarterly. Last review: 2 July 2026. Corrections to the legal analysis are genuinely welcome — write to us and we will publish an amendment with attribution.

Cite this page

VPSDEN, “How to choose an offshore hosting jurisdiction (2026)”, vpsden.com/kb/offshore-vps-jurisdiction-guide, revised 2026-07-02. Published under CC BY 4.0 — reproduce it freely, with attribution.

Found an error? We amend the article and name the reader who reported it. Tell us.

Offshore VPS from €4.40/month. No KYC, no email, paid in Monero.

Nine jurisdictions, RAM-only options, disks we cannot read, live in about 48 seconds.

No email · No KYC · Pay in Monero · Deployed in under a minute