ALL SYSTEMS OPERATIONAL 14 REGIONS · 1.2 TBPS SHIELD TOP-UP WITH BTC · XMR · LTC · ETH · USDT +3 COINS

PRIVACY

How to choose an offshore server location

14 min read

How to choose an offshore server location

Every deploy screen asks you the same question near the end, and almost nobody thinks about it: where should this machine physically be? Most people pick whatever is closest, or whatever is first in the list, and move on. That is the one choice on the page that cannot be undone later without copying a running service to a new box — and it is also the choice that decides who can compel your provider, what records exist about you at all, and how far a complaint has to travel before someone has to answer it. It deserves more than two seconds. What follows is how to think about it honestly, including the parts the offshore-hosting industry tends to leave out.

Jurisdiction is a friction setting, not a shield

The single most useful correction to make before comparing countries is this: choosing a location does not put your server outside the law. It changes which law applies, who has to be convinced, and how long that takes. Those are enormous practical differences, and they are not the same thing as immunity. A host in a privacy-friendly jurisdiction is not obliged to act on a templated complaint email from a foreign rights-holder — that is real and it matters. The same host will still respond to a valid order from a court that actually has authority over it.

Read the marketing with that filter on and most of it resolves cleanly. "DMCA-ignored" means the United States notice-and-takedown process does not bind a provider outside United States jurisdiction, which is simply a description of how territorial law works — we cover the mechanics in offshore and DMCA-relaxed hosting explained. "Bulletproof" means something else entirely and usually means trouble, which is the subject of offshore versus bulletproof hosting. What you are actually shopping for, in nearly every legitimate case, is friction: enough legal distance that automated complaints and speculative fishing do not translate into an instant takedown, without pretending that anything on the public internet is beyond reach.

The five questions a location actually answers

Strip away the flags and the marketing copy and a region is answering five separate questions. Conflating them is where most bad decisions start, because a country can score brilliantly on one and poorly on another.

  • Who can compel the operator. A hosting company answers to the courts of the country it operates in. Every other authority in the world has to go through a treaty process, a local court, or a request the operator is free to decline. This is the question "offshore" is really about.
  • What records exist in the first place. Compulsion only ever produces what somebody already stored. A jurisdiction with no blanket data-retention mandate lets a provider keep minimal logs lawfully, and no order can extract a record that was never written.
  • Who else is upstream of you. Your host sits behind transit carriers, an IP allocation, and — if you use one — a domain registrar, each in its own jurisdiction. A complainant blocked at the host frequently just walks one hop up the chain.
  • How far the packets travel. Physics does not care about your threat model. Every kilometre between your server and the people using it is latency you pay on every single request, forever.
  • What the local law itself forbids. A country outside your adversary's reach may have content and surveillance rules of its own that are stricter than the ones you left. Distance from one legal system means proximity to another.

A good choice is the one that scores well on the questions that matter for your specific workload, and consciously accepts a poor score on the rest. There is no region that wins all five, and any provider claiming otherwise is selling you something.

Data retention: the law that decides what exists to hand over

This is the most consequential and least discussed factor. Surveillance debates focus on access, but access is downstream of storage — an order compels disclosure of records that exist, and creates nothing. So the question worth asking about a jurisdiction is not "can they demand data" but "is my provider legally required to be generating data about me in the first place".

  • Blanket retention mandates in Europe are far weaker than their reputation. The EU-wide directive that required mass retention was struck down by the Court of Justice in 2014, and national laws attempting to replicate it have been repeatedly found incompatible with EU law since. Several member states currently have no enforceable general-retention obligation at all.
  • Romania is the clearest example and a real reason Bucharest keeps appearing in privacy hosting. Its constitutional court struck down the national data-retention law, then struck down the replacement, on the grounds that indiscriminate retention is incompatible with constitutional privacy rights.
  • Retention rules usually target telecom and access providers, not hosting companies. The distinction matters more than the country in a lot of cases: an obligation written for the operator connecting subscribers to the internet often does not extend to a company renting you a virtual machine.
  • What the provider chooses to keep is the other half, and it is entirely policy rather than law. Two hosts in the same country can have completely different answers, and the one that keeps ninety days of everything is worse for you than a stricter jurisdiction with a minimal-logging operator.
  • Payment records are the retention question that actually catches people. A host with immaculate server-log hygiene that also holds your card number and billing address has a complete identity file on you, and it will outlive the server by years.
The practical hierarchy is worth memorising: what was never collected beats what was collected and deleted, which beats what is retained under a short policy, which beats what a law requires to be kept. Choose the jurisdiction to enable the top of that list, then choose an operator who actually lives there.

The Eyes alliances, minus the marketing

Every offshore hosting page cites the Five, Nine and Fourteen Eyes, usually as a simple blocklist. The underlying thing is real: an intelligence-sharing arrangement that began between the United States, the United Kingdom, Canada, Australia and New Zealand, widened to include Denmark, France, the Netherlands and Norway, and widened again to add Germany, Belgium, Italy, Spain and Sweden. It is worth knowing about. It is also routinely applied to the wrong problem.

Those arrangements concern signals intelligence between state agencies. They are close to irrelevant to the ordinary threats a normal server faces — a copyright complaint, a competitor's abuse report, a civil subpoena, a hosting provider that folds under pressure. Treating alliance membership as the only variable produces genuinely poor decisions, and the Netherlands is the standing example: it is a Nine Eyes member and simultaneously one of the best places in the world to host, with superb connectivity, a mature legal regime that expects actual legal process rather than a form email, and strong data-protection law. Ruling out Amsterdam on a Wikipedia list while ignoring retention law, provider policy and your own payment trail is optimising the least important term in the equation.

The alliances matter if your adversary is a state intelligence service, in which case your hosting choice is a small part of a much larger problem and a guide is not what you need. For everyone else, the ranking that predicts real outcomes is: what the provider knows about you, what the local law forces the provider to store, how hard it is for a foreign party to compel anything, and only then which treaties the government has signed.

The eight privacy-tier regions, one by one

Our network runs 14 regions, eight of which we classify as privacy-tier. That label is not a claim of legal immunity — it means the region combines a legal environment that requires proper process, a network that does not fold on receipt of an automated notice, and infrastructure we operate rather than resell. Here is the honest character of each, including the drawback.

  • Amsterdam, Netherlands. The best-connected location on the list and the default correct answer for most European traffic. Excellent peering, a legal system that expects real process, strong data-protection law — set against Nine Eyes membership and a rights-holder ecosystem that is well organised and knows how to file properly.
  • Bucharest, Romania. Unusually strong constitutional privacy jurisprudence after its courts twice struck down data-retention legislation, EU-grade infrastructure at noticeably lower cost, and good latency to the whole of eastern and central Europe. Peering is a step below Amsterdam and Frankfurt.
  • Zurich, Switzerland. Outside the EU, with a deep-rooted legal culture of privacy and a high bar for foreign requests, which have to run through formal channels rather than arriving by email. It is not a legal void — Swiss authorities cooperate with valid international requests — and it is the most expensive place on the list.
  • Reykjavik, Iceland. A genuinely distinctive free-expression environment, no ties to the Five Eyes core, cool climate and cheap geothermal power. The trade is geography: every packet crosses a submarine cable, so expect a meaningful latency penalty from anywhere that is not the North Atlantic.
  • Helsinki, Finland. Politically stable, outside the Fourteen Eyes, excellent infrastructure and the shortest hop into the Baltic and Russian-speaking internet. Finland did expand its intelligence-gathering powers in recent years, so it is strong rather than absolute.
  • Luxembourg. A small jurisdiction with a long institutional tradition of confidentiality and one of the more privacy-attentive regulators in the EU, hosting a disproportionate amount of European financial infrastructure. Capacity is limited compared with the big hubs and pricing reflects that.
  • Kuala Lumpur, Malaysia. Genuinely outside the European and American legal orbit, which is the entire point, with good reach into South-East Asia. Balance that against Malaysia's own content and communications laws, which are not permissive, and latency to Europe or the Americas that you will feel.
  • Moscow, Russia. Effectively unreachable by Western civil process, which for some workloads is exactly the requirement. It also has some of the most demanding domestic data and surveillance legislation anywhere, so this is a clear trade of one legal exposure for a different and larger one rather than a general-purpose privacy upgrade.

If you want a default and you do not have a specific reason to deviate: Amsterdam for European audiences, Bucharest when you want distance from the western-European rights-holder machinery without giving up EU infrastructure, Zurich when the priority is a high procedural bar, and Kuala Lumpur when the priority is being outside the Euro-American system entirely. Reykjavik is a deliberate choice you make with the latency budget open in front of you.

The six standard regions, and when they are the right answer

The other six — Frankfurt, Paris, London, New York, Singapore and Tokyo — are ordinary well-connected locations in ordinary jurisdictions. They exist because a great many workloads have no adversarial dimension at all and are simply better served by being close to their users.

  • The workload is latency-bound and the audience is regional. An application serving Japan from Tokyo is straightforwardly better than the same application served from Iceland, and no amount of jurisdictional theory changes that.
  • The content is entirely unremarkable. A company site, an internal tool, a staging environment or a personal project attracts no complaints, so buying friction against complaints purchases nothing.
  • You need the deepest possible peering. Frankfurt and New York sit on top of two of the largest exchanges on earth, and for high-egress workloads that is a measurable difference.
  • The privacy you need is at the account layer, not the map. Paying from a crypto balance with no identity attached gives you the same anonymity in Frankfurt as in Reykjavik — jurisdiction is about resisting compulsion, not about whether your name is on the machine.
  • It is one node among several. Multi-region deployments routinely mix a privacy-tier home for the data with standard-tier edges for reach, which is a sensible architecture rather than a compromise.

That last point is worth dwelling on, because it is the most common mistake in the other direction. People choose a far-away privacy-tier region for a workload that has no threat model, pay the latency every day for years, and gain nothing they could not have had by paying in Monero from a burner email in Frankfurt. Privacy at the account layer and friction at the jurisdiction layer are independent purchases, and most people only need the first.

Latency is a real cost — do not pay it for nothing

Distance is the one factor in this entire discussion that is not a matter of interpretation. Light in fibre covers roughly two hundred kilometres per millisecond, and real routes are never straight, so a rough working rule is about one millisecond of round trip for every hundred kilometres of separation, plus whatever the path adds in switching and detours.

  • Within a region — Amsterdam to Frankfurt, Zurich to Paris — you are in single-digit milliseconds, and the location is effectively free from a performance standpoint.
  • Across Europe, roughly ten to forty milliseconds. Bucharest and Helsinki serve western Europe perfectly well; this range is invisible for most applications.
  • Iceland to continental Europe adds a submarine-cable leg, typically landing in the twenty to forty millisecond band, and the trans-Atlantic leg is materially longer.
  • Europe to South-East Asia is the big one, commonly a hundred and fifty milliseconds or more each way. On a chatty protocol that multiplies into something users describe as broken.
  • Interactive workloads suffer worst. A remote desktop, an SSH session or a database doing many small round trips amplifies latency directly, while bulk transfer and batch jobs barely notice it.
Test before you commit rather than reasoning about it. Deploy the cheapest instance in your two shortlisted regions, measure the round trip from where your users actually are, and keep the one that wins. At $3.99/mo and about a minute to provision, that experiment costs less than the time spent arguing about it — and a region is the one setting you cannot change later without a migration.

Picking a region: a short decision procedure

  1. 01Write down the actual adversaryA rights-holder bot, a competitor filing abuse reports, a civil litigant, a curious employer, a national intelligence service — these need completely different answers. If the honest response is "nobody in particular", you want the standard tier and you have just saved yourself a lot of latency.
  2. 02Locate your users on a mapNot where you are — where the traffic comes from. This sets the latency budget, and for most workloads it eliminates more options than every legal consideration combined.
  3. 03Decide whether the workload is interactiveRemote desktops, SSH-heavy work and live applications are punished by distance. Nodes, relays, backups, batch processing and storage are almost indifferent to it, which is what makes them free to place far away.
  4. 04Check what the local law forbids, not just what it permitsA jurisdiction outside your adversary's reach may restrict your content in ways your home country does not. Read the destination as a place with its own rules rather than as an absence of rules.
  5. 05Follow the chain above your hostTransit providers and, above all, your domain registrar are separate jurisdictions with separate policies. A complainant stopped at a resilient host very often succeeds one hop up, and a registrar that folds takes your name down regardless of where the disk is.
  6. 06Fix the account layer before the map layerSign up with an email that is not tied to you, pay from a crypto balance, and keep the machine out of your legal name. This is cheaper, faster and more effective than any region choice, and it is the step people skip.
  7. 07Shortlist two regions and measure bothOne privacy-tier candidate and one convenience candidate. Deploy the smallest instance in each, run your own traffic against them for an hour, and let the numbers decide instead of the map.
  8. 08Plan for being wrongKeep configuration reproducible and backups portable, so that changing your mind about a region is an afternoon rather than a crisis. This is good practice regardless, and it removes most of the pressure from the decision.

What a server location cannot do for you

Jurisdiction shopping has a well-defined ceiling, and running into it is how people end up badly exposed while feeling well protected. These are the things no country on any list will fix.

  • It cannot undo a payment trail. If the server was bought with a card in your legal name, the machine is in your legal name in every jurisdiction on earth. That is settled at signup, before the region dropdown is ever touched.
  • It cannot patch your software. A vulnerable application is compromised in Reykjavik exactly as fast as in New York, and an attacker does not file paperwork.
  • It cannot hide the domain. A registrar holds your identity even behind WHOIS privacy, and every certificate you issue publishes the exact hostname into public transparency logs anyone can search.
  • It cannot protect data you send elsewhere. Analytics, error tracking, a CDN, an email relay, a payment processor — each one ships your users' data into its own jurisdiction, and the strictest server location does not follow it there.
  • It cannot conceal your own connections. If you administer the box from your home address over plain SSH, the connection metadata exists at both ends whatever the flag on the rack.
  • It cannot make illegal content legal. Genuinely unlawful material is unwelcome on every serious network, ours included, and no jurisdiction is a licence for it.
  • It cannot compensate for an operator who keeps everything. A privacy-tier country in front of a provider logging every request for a year gives you a comfortable-sounding address and no actual privacy.

The pattern in that list is that jurisdiction is one layer among several, and it is neither the first nor the most effective. The layers that do more work, in order, are: not attaching an identity at signup, paying in a way that cannot be traced back to you, keeping the machine itself hard to break into, and only then choosing where it sits. If you have not read what no-KYC hosting means and why Bitcoin is pseudonymous rather than anonymous, those two matter more than this page does — and topping up in Monero is what closes the on-chain trail if it matters to you.

Mistakes that make the choice worse than random

  • Choosing purely from an Eyes-alliance list, which optimises against intelligence agencies while ignoring the retention law, provider policy and payment trail that decide almost every real outcome.
  • Paying a hundred and eighty milliseconds of latency forever for a workload nobody was ever going to complain about.
  • Assuming offshore means unaccountable, then discovering that the local regulator has content rules stricter than the ones you were avoiding.
  • Hardening the host beautifully and registering the domain through a mainstream registrar in your own name, which reopens the whole question in one step.
  • Treating a country's reputation as its current law — Europe's retention landscape in particular has changed substantially, in both directions, and most articles about it are years out of date.
  • Placing a database far from the application that queries it, so that every page load pays the round trip several times over.
  • Choosing a jurisdiction for the server and leaving the backups with a provider in a completely different one, which quietly makes the backup provider the weakest link.
  • Deciding once and never revisiting, when laws, cable routes and your own traffic patterns all change over a few years.

Do the boring parts and the map becomes a much smaller decision than it looks. Sign up without an identity, fund the balance in crypto, harden the box in the first ten minutes, keep your administrative access behind a WireGuard tunnel, and keep the backups somewhere you control. Then choose the region for the reason that actually applies to your workload — friction against complaints, distance from a specific legal system, or simple proximity to your users — and accept the trade you are making with your eyes open. All 14 regions cost the same on every VPS plan, so the only currency you are ever spending here is latency.

None of this is legal advice, and it is not a substitute for it. It is an orientation to the variables that actually differ between regions, so that you can ask a qualified person a sharper question if your situation genuinely calls for one.
Ready to try it?Deploy Offshore VPS from $3.99/mo — no KYC, paid in crypto. Get started