RoPA Pilot

OVHcloud and GDPR: hosting, non-EU transfer and DPA

OVHcloud is published by OVH SAS. If your teams use it, it is a processor within the meaning of Article 28 GDPR and it must appear in your record of processing activities.

Vendor (processor)
OVH SAS
Headquarters
European Union
EU hosting
EU by default
Non-EU transfer
No
Transfer mechanism
European Union
Category
Cloud / Hosting
Typical personal data
identity, contact details, technical data, financial data
Detected domains
ovh.com, ovhcloud.com

Does using OVHcloud mean a non-EU transfer?

No. OVH SAS keeps the data inside the European Union: no structural transfer to document under Chapter V.

What to write in your Article 30 record

Purpose: Cloud / Hosting. Categories of personal data: identity, contact details, technical data, financial data. Recipient: OVH SAS. Transfer: European Union. Retention: aligned with the contract or the account lifetime, whichever is shorter.

How RoPA Pilot handles it

RoPA Pilot detects OVHcloud from the domain name of the tab — never from page content — and pre-fills the record above in one click. The extension flags the record if the transfer mechanism is missing or unverified.

Indicative information from public sources. The transfer mechanism actually applicable to you is the one written in your contract.