Data location attestation: how to get it and what it's for
What is a data location attestation? The data location attestation is an official document issued by Hodi SAS that certifies the physical location where your server or web hosting data is hosted. This document states the exact data center, with the precise address of the infrastructure. Download a sample What is this attestation for? This attestation addresses several regulatory and business needs: **GDPR and local lawSome readersHodi is a French company. Is my data subject to foreign legislation?
This is a legitimate question, and the answer comes in two parts. Hodi is a French company, and therefore subject to the GDPR, the most demanding data protection framework to date. In practical terms, no foreign authority can demand access to data we host solely on the basis of its own national legislation: the GDPR makes this type of transfer conditional on an international agreement, such as a mutual legal assistance treaty (Article 48 of the GDPR). **Being French is a further layer of protecFew readersWhat is the Cloud Act, and am I affected by hosting with Hodi?
The Cloud Act is a 2018 US law that allows US authorities to request access to data held by providers with a connection to the United States, even when that data is stored elsewhere. The key point: what triggers the Cloud Act is not where your data is located, it is the nationality or the ties of the technical provider. Data stored in a datacenter in Dakar or Abidjan can remain within the scope of the Cloud Act if an American link is involved in the chain. Conversely, **the more European and AfFew readersCan you sign a DPA (Data Processing Agreement)?
Yes. As a hosting provider and a French company subject to the GDPR, Hodi can provide you with a DPA (Data Processing Agreement), i.e. a data processing agreement within the meaning of Article 28 of the GDPR or local personal data protection laws. Who is responsible for what? Personal data protection laws distinguish between two roles: The data controller: that's you, the customer, who decides why and how your data is processed. The data processor: that's **HFew readersWhat should I do if a data localization law passes in my country?
More and more African countries are adopting or preparing laws requiring certain data to be stored within national territory. If this is the case in your country, or if you expect it to happen, here is what to do. 1. Map your data. Know precisely what data you process, where it is stored, and where it transits. Many businesses do not know this with certainty, and it is the starting point for any compliance effort. 2. Identify what's sensitive. Not all data carries the same level of reqFew readersWho is responsible for what?
The GDPR distinguishes two clear roles in the processing of personal data. You are the data controller, Hodi is your data processor. This split isn't a legal technicality: it defines who decides what, and who is accountable for what. You, the data controller You determine why and how personal data is processed. In practical terms, that means you: define the purposes (what the data is used for) and the legal basis; decide which data is collected; inform your users and manage theirFew readers