Skip to content
Summer 2026: 20% off 12-month terms with code ATLAS10 stacked on top
Guides 10 min read

Offshore hosting explained: what jurisdiction actually buys you

What 'DMCA ignored' really means, why six jurisdictions and not twenty, the difference between a privacy host and a bulletproof one, and the four things offshore hosting cannot do for you.

ML

Marek Lindqvist

Infrastructure Security

Published

Quick answerOffshore hosting means your server sits in a jurisdiction chosen for its law rather than only its latency. Concretely: no blanket obligation on the provider to retain records about you, no direct legal force for a United States DMCA notice, and disclosure that requires a court in that country. It does not mean immunity from law, and it does not mean abuse is tolerated.

The term is doing a lot of unearned work

“Offshore” appears on the front page of hundreds of hosting companies, usually next to a shield icon and the words DMCA IGNORED in capitals. Almost none of them say which jurisdiction, which statute, or what actually happens when a complaint arrives. That vagueness is the product.

The concept underneath is real and worth understanding, so here is the version with the specifics filled in.

What "DMCA ignored" means, precisely

The Digital Millennium Copyright Act is a United States federal statute. It creates a notice-and-takedown regime, and a safe harbour, for service providers within US jurisdiction. That is the whole of its reach.

A server in Reykjavík is not within US jurisdiction. When a US-form DMCA notice arrives about it, the notice has no operative legal effect on us — there is no statutory obligation to disable anything, and no safe harbour to lose by declining. So we record the notice, forward it to the customer, and take no further action.

That is the entire claim. It is narrow, it is accurate, and it is worth having. What it is not:

  • It is not a claim that copyright does not apply. Iceland has copyright law. So do Switzerland, Panama, Romania and Bulgaria.
  • It is not a claim that a properly-brought local complaint is ignored. If a rights holder pursues a claim under Icelandic law through Icelandic process, Icelandic law applies to us.
  • It is not a claim about anything except copyright notices. Criminal process is a different question with a different answer.

A host that tells you it ignores all legal process everywhere is either misinformed about how jurisdiction works or is lying to you, and in both cases you are trusting your infrastructure to bad judgement.

Why data retention is the part that matters more

Takedown notices get the marketing attention; retention mandates matter more day to day.

Several jurisdictions oblige providers to log connection data about customers and keep it for a fixed period, available on request. Where such a mandate exists, a host's privacy policy is largely decorative — the data exists because the law says it must.

The six jurisdictions we use do not impose a blanket retention obligation on hosting providers:

JurisdictionRetention position
IcelandNo mass-retention mandate for hosts; strong constitutional speech protections
SwitzerlandOutside the EU and its disclosure instruments; strict federal data-protection act
PanamaNo hosting retention mandate; not party to US or EU frameworks
RomaniaConstitutional court struck down blanket retention twice — 2014 and 2020
BulgariaNo hosting mandate beyond the EU baseline
NetherlandsRetention law struck down in 2015; notices must be specific and substantiated

The practical consequence is that our data-minimisation choices are ours to make rather than something a statute overrides. We hold an email address, invoice records, support tickets, resource metrics and a 90-day authentication log. Traffic contents are never inspected or retained, and netflow headers are sampled for 72 hours purely to drive DDoS mitigation before being discarded.

Why six regions and not twenty

We run twenty datacenters. Six are offshore. The other fourteen — New York, Dallas, Los Angeles, Toronto, London, Frankfurt, Paris, Warsaw, Singapore, Tokyo, Sydney, Mumbai, Dubai, São Paulo — are chosen for latency and peering, and local legal process applies to them in the ordinary way. The DMCA is actionable in the US regions.

We could describe all twenty as privacy-focused. It would be better marketing and it would be false, and the moment a customer discovered it every other claim we make would be worth nothing. It would also be bad advice: if your users are in Sydney, an Icelandic server is a worse product for you, and you should know that before you buy rather than after.

Offshore is not bulletproof, and the difference is the whole thing

These two categories use identical vocabulary and are completely different businesses. The distinguishing question is not where the servers are. It is what happens when an abuse report arrives.

A bulletproof host does nothing, deliberately, and sells that as a feature. A privacy-respecting host chooses its jurisdiction carefully and still terminates abuse. We are the second kind. Spam, phishing, malware distribution and command-and-control, credential stuffing, DDoS origination and CSAM get you terminated without refund in Reykjavík exactly as in Dallas. Reports are triaged within four hours, forwarded to you with a 48-hour remediation window when the matter is not urgent, and acted on immediately when there is live harm.

That is not squeamishness, and I want to be honest that the commercial argument is at least as strong as the ethical one. A network that tolerates abuse gets its IP ranges onto Spamhaus and every commercial blocklist within weeks. At that point every legitimate customer on those ranges finds their mail bouncing, their API calls challenged and their visitors staring at a CAPTCHA. Tolerating abuse destroys the product for the people paying for it.

So when you are evaluating a host that advertises offshore jurisdiction, the diagnostic question is: do they publish an acceptable use policy, and does it prohibit anything? If the answer is no, what you are buying is not privacy — it is a neighbourhood, and you will be sharing it.

Four things offshore hosting cannot do for you

1. It cannot protect you from your own application

By far the most common failure. Jurisdiction is irrelevant if your software announces who you are: a personal domain in a mail header, an analytics property shared with your other sites, a reused SSH key, a git config with your real name baked into every commit, a TLS certificate ordered with a real address. We have watched customers build an admirable stack on top of an Icelandic instance and then leak the whole thing through a WHOIS record.

2. It cannot undo a payment trail

If you funded the purchase from an exchange account tied to verified identity, on a transparent chain, that link exists regardless of where the server sits. This is why we accept Monero — not as a gimmick, but because it is the only asset we take where the payment itself does not create a public trail.

3. It cannot protect a compromised server

An attacker with root does not care about the jurisdiction. Move SSH or RDP off the default port, restrict it to your own IP, use keys rather than passwords, and take snapshots. Our hardening checklists cover both platforms and take about fifteen minutes.

4. It cannot guarantee the law stays put

Jurisdictions change. Romania's retention law was struck down in 2014, reintroduced, and struck down again in 2020. Any host claiming a permanent guarantee is describing a world that does not exist. What we can commit to is telling you when something changes, and letting you move regions with a snapshot restore at no cost.

How to evaluate an offshore claim in five minutes

  1. Which country, and which facility? A host that will not name the building is reselling something and does not know either.
  2. Ask for a test IP and check the /24 on Spamhaus. A range full of listings tells you exactly what the neighbours are doing.
  3. Look up the ASN on bgp.he.net. Do they announce their own space, and since when?
  4. Read the AUP. If nothing is prohibited, that is your answer.
  5. Check what they claim about legal process. "We comply with valid local process and push back on overbroad requests" is a host that has thought about it. "We ignore all requests" is a host that has not.
Apply it to usOur jurisdictions, facilities and test IPs are on the locations page, the ASN is AS212744, and the acceptable use policy states plainly what gets you terminated. Run the checklist. We would rather you buy with your eyes open — see the offshore overview for the per-jurisdiction detail.
#offshore#dmca#jurisdiction#privacy#buying guide
ML

Marek Lindqvist

Infrastructure Security

Runs our hardening baselines and incident response. Previously a network engineer at a Nordic transit provider.

Put this into practice for $5 a month

Windows RDP from $12/month, Linux VPS from $5/month, delivered in about four minutes with a 72-hour money-back guarantee.