What your website sends outside the EU

Yes, your website transfers data outside the EU whenever one of its pages calls a service located elsewhere. The visitor's IP address travels with every request, and the EU Court of Justice ruled in 2016 that it can be personal data.

The European Data Protection Board explains the general rules on transfers. This guide starts from your website: what it sends, and to whom. It is one of the points the hosting and dependency audit covers.

Why a web page sends data outside the EU

A page is almost never served by one server alone. It loads fonts, an analytics tool, an embedded video, a map, a bot check. Each of these services receives a request from the visitor's browser, with their IP address and often the address of the page they are reading.

If the service runs outside the EU, or its company is subject to another country's law, that request is a transfer under the GDPR. It often happens as soon as the page opens.

What we find on the sites we audit

85%send personal data outside the EU without safeguards during a simple visit

This percentage covers about 30 websites we audited between August 14, 2026 and September 24, 2026, the ones where this point could be checked. Many were audited because a defect showed up quickly, so the figure describes our audits, not websites in general.

What the audit records on your pages

The audit opens your pages like a visitor would, in a fresh browser, before any interaction. It records:

  • every service called, on every page in scope, not just the home page;
  • the company behind it and the law it is subject to;
  • what travels with the request, starting with the visitor's IP address.

A product page, the contact page and the checkout page don't call the same services. That is why the audit looks at all of them, not one sample page.

The GDPR accepts several bases: an adequacy decision by the European Commission (the EU-US Data Privacy Framework is one, for companies on its official list), standard contractual clauses, or, in specific cases, the Article 49 derogations. Checking that a provider has one belongs in your record of processing: a web page does not show it.

Transfers are not the only question. A provider subject to US law may have to hand data to its own authorities, even when that data is stored in Europe: that is what the CLOUD Act provides.

Send less from your website

  • Serve fonts from your own server.
  • Load videos and maps only when the visitor asks for them.
  • Choose an analytics tool run by a European company.
  • Remove scripts nobody uses anymore.

And the hosting itself

Third-party services are only part of the path. The guide on EU web hosting covers your host, DNS, content delivery and email.

What this check doesn't tell you

We observe the requests made by the pages we visit, and the country of each recipient. We cannot see your contracts, your providers' clauses, or data sent from your server or internal tools.

This guide is not legal advice. Whether a transfer is lawful is a question for your data protection officer or a lawyer.

By Quentin Mathis, Z29K · updated September 25, 2026

Read next

CLOUD Act: is your website exposed?

The CLOUD Act reaches data held by US providers, even on servers in Europe. Which layers of your website it covers, and what the audit looks at.

Read the guide →

EU web hosting: more than server location

A server in the EU is not enough: your host's jurisdiction, DNS, CDN and email matter too. The questions to ask before you choose.

Read the guide →