Renting a server in Germany or Austria: location, latency and GDPR

Published on 10 min read

Latency, jurisdiction and connectivity: why the server location decides things that no later upgrade can change, what Frankfurt at DE-CIX means for users in Vienna or Munich, and which points to check before you order.

If you want to rent a server, most comparisons put prices, CPU cores and gigabytes in front of you. The location turns up as a footnote, even though it decides things that no later upgrade can change: how fast your users reach the server, which law applies to the data on it and how well the datacenter is connected to the network. This article works through those three points one after the other, using the facts about KernelHost as the example: company headquarters in Vienna (Austria), main datacenter maincubes in Frankfurt am Main (Germany), storage servers in Nuremberg.

One qualification up front: what follows on data protection is a technical and organizational description, not legal advice. Whether your specific processing is lawful depends on your use case, not on the location alone.

Three dimensions in which the location counts

  • Latency to your users: every packet needs time for the trip. The closer the server sits to the people who use it, the shorter the response times.
  • Jurisdiction and data protection: the location of the datacenter and the registered office of the provider determine which law applies and which authorities are competent.
  • Connectivity and infrastructure: a server is only as reachable as the network it hangs on, and only as available as the power, the cooling and the access control of the building.

The three points do not always pull in the same direction. A location with excellent connectivity can still be far away from your users, and the nearest location is not necessarily the one with the right legal framework. That is why it pays to check all three separately.

Latency: Frankfurt as an internet exchange hub

With DE-CIX, Frankfurt am Main is the largest internet exchange point in Germany. Network operators, access providers and content providers swap their traffic directly there. For a server that means short paths: packets going to a user in Germany, Austria or Switzerland usually pass only a few intermediate hops, because the networks converge in Frankfurt anyway. The maincubes datacenter that houses the KernelHost host systems sits only a few hundred metres from DE-CIX.

How much latency you see from your city to Frankfurt depends on your access provider, on where that provider interconnects and on your own line (fibre, cable, DSL, mobile). The values below are rough figures from experience for the round-trip time (ping) measured from a well-connected fixed line. They are neither a guaranteed measurement nor a promise, just an order of magnitude for planning:

Starting pointTypical round-trip time to Frankfurt (from experience)
Munichroughly 5-8 ms
Zurichroughly 6-10 ms
Amsterdamroughly 6-10 ms
Berlinroughly 8-12 ms
Viennaroughly 10-15 ms
Warsawroughly 18-25 ms

Mobile connections and older DSL lines add a good deal on top of that in practice, no matter where the server stands. For comparison: a datacenter in Vienna would save a user in Vienna maybe ten milliseconds. For a website, a shop or a business application that difference is not noticeable, because database queries, TLS handshakes and rendering in the browser set the pace there.

When proximity to your users decides it

Things look different when every millisecond lands directly in the application:

  • Game servers: players notice the difference between 15 and 60 ms. If your players are spread across Europe, Frankfurt puts you in the middle of them. For a community in North America or Asia, the server belongs there.
  • VoIP and voice servers: with speech, both the round-trip time and its variation (jitter) count. The same rule applies here: as close to the participants as possible.
  • Remote desktop and interactive consoles: every keystroke travels there and back once.

For backups, batch processing, build servers, archives and mail servers, on the other hand, the location hardly matters. What counts there is throughput, not round-trip time, and whether a backup runs at 12 or at 25 ms of ping changes almost nothing about how long it takes.

Jurisdiction: Austria and Germany, both in the EU

Two places are relevant at KernelHost, and they should not be mixed up. Your contractual partner is KernelHost GmbH, based in Vienna and entered in the Austrian commercial register under FN 646015 y. The servers stand in the maincubes datacenter in Frankfurt am Main, the storage servers in Nuremberg. Both countries are members of the EU, and the General Data Protection Regulation applies directly in both. Payment data is processed solely to settle the transaction.

Three points matter for your own assessment:

  1. The responsibility stays with you. If you process personal data on a rented server, you are the controller in the sense of the GDPR. The provider supplies hardware, network and building. What happens on the server, who has access and how long data sits there is yours to decide and yours to answer for.
  2. Processing on behalf of a controller. If you process third-party data, customer records in a shop for example, you normally need a data processing agreement with the host. Sort that out before you go into production, not afterwards.
  3. The location by itself does not trigger a transfer to a third country. Data stored in Frankfurt or Nuremberg does not leave the EU merely because the server stands there. Whether your application sends data to third countries depends on what you pull in: external fonts, analytics services, payment services, mail relays. That is a question of your configuration, not of the datacenter.

Once more in plain words: this is not legal advice. If you process sensitive data, have your use case reviewed by a professional.

Datacenter and connectivity: maincubes Frankfurt am Main

The host systems for KVM root servers, Professional root servers, game servers and web hosting stand in the maincubes Premium Datacenter in Frankfurt am Main. The datacenter is TÜV TIER3+ certified. The power supply is laid out redundantly and backed by UPS systems and emergency generators, and 100% of the electricity comes from renewable sources. On the network side, every switch is attached to the core router with at least 2x 40 Gbps over fibre. The details are on the datacenter page.

DDoS protection is part of the location, because a server without protection stays reachable only until somebody attacks it. KernelHost filters attacks permanently and in real time, without switching off the IP address under attack (no null routing). The capacity depends on the product line: the standard lines, meaning KVM root servers, dedicated servers, game servers and web hosting, are covered by 3.2 Tbps of Arbor DDoS protection, the Professional root servers and Professional dedicated servers by 17 Tbps. In every case the protection is included at no extra charge. More on that on the DDoS protection page.

Other locations and what they are meant for

Frankfurt is the core, but not the only location. The locations page lists every current region, and sorted roughly by purpose it looks like this:

  • Unlimited Traffic KVM servers: virtual servers without a traffic cap, and you pick the location in the order form. Besides Germany you can choose London, Strasbourg, Warsaw, Helsinki, Beauharnois in Canada, New York, St. Louis, Seattle, Singapore, Tokyo, Seoul, Mumbai and Sydney, each with the 3.2 Tbps DDoS protection. Meant for projects whose users sit outside Central Europe, or for applications with permanently high data volumes.
  • VPN servers: the basic and gaming variants run in Germany, while you deploy the Unlimited and High Speed variants at a location of your choice in Europe, North America, Asia or Australia. Here the location decides which address you appear under on the internet.
  • Storage servers in Nuremberg: storage from 1 to 20 TB, reachable over FTP, SFTP, SCP, Samba, WebDAV, BorgBackup and rsync, with snapshots and encryption of the stored data. The fact that Nuremberg is not Frankfurt is an advantage for backups: a backup in a different datacenter from the server also survives the loss of an entire site.
  • Dedicated servers: the standard line stands in Frankfurt am Main or Nuremberg, the Professional line in Frankfurt am Main.

Checklist before you order

  1. Define your audience. Where do the people who will use the server sit? For Central Europe, Frankfurt is the obvious choice. If your users are mostly in North America or Asia, take an Unlimited Traffic KVM server at the matching location.
  2. Measure the latency instead of guessing it. KernelHost runs a test server at test.kernelhost.info. A ping test.kernelhost.info shows the round-trip time, and mtr -rwc 100 test.kernelhost.info additionally shows every hop along the way together with the packet loss. Measure at different times of day and from the lines your users actually use.
  3. Estimate how much traffic you need. KVM root servers in Frankfurt run on a 2x 1 Gbps connection with fair-use traffic, which is enough for websites, applications and most game servers. If you deliver large volumes of data around the clock, go for dedicated servers with unlimited traffic or for the Unlimited Traffic KVM servers.
  4. Backup strategy before the first byte. KVM root servers come with three backup slots, among them a weekly automatic emergency backup. That does not replace a backup of your own in a second place, on a storage server in Nuremberg for example. How to set that up cleanly is described in a backup strategy for root servers.
  5. Pick a payment method. PayPal, credit and debit card, Apple Pay, Google Pay, SEPA direct debit, Sofortüberweisung, paysafecard, cryptocurrencies, WeChat Pay and Alipay are available, with no surcharge on the price. With SEPA direct debit the booking takes 1-3 business days, with cryptocurrencies it takes until the confirmation in the respective network, and every other method is confirmed immediately. The overview: payment methods.
  6. Check the term and the cancellation rules. All products run PrePaid: you pay for a period in advance, there is no contract, no minimum term, no notice period and no automatic renewal unless you switch it on yourself. A server you do not renew simply expires at the end of the paid period.
  7. Plan for the first 30 minutes. A new server is reachable from the first minute, and it is scanned from the first minute. Updates, users, SSH and the firewall belong right at the start: setting up a new root server.

Conclusion

For users in Germany, Austria and Switzerland, a server in Frankfurt am Main is the right choice in most cases: short paths over DE-CIX, a TÜV TIER3+ certified datacenter and a legal framework inside the EU, no matter whether the provider is based in Vienna or in Germany. A datacenter in Austria would save users in Vienna a few milliseconds and offer the same EU framework; the national details differ, but that changes nothing about the GDPR. What matters more is that you measured the latency yourself before ordering, judged your traffic needs realistically and planned the backup in a second place. If you want to start from there, you will find the configurations under rent a KVM root server from €9.99 a month and rent a dedicated server from €69.99 a month, both PrePaid and without a contract.

Frequently asked questions

Where are the KernelHost servers located?
The host systems for KVM root servers, Professional root servers, game servers and web hosting stand in the TÜV TIER3+ certified maincubes datacenter in Frankfurt am Main (Germany). Dedicated servers of the standard line stand in Frankfurt am Main or Nuremberg, storage servers in Nuremberg. Unlimited Traffic KVM servers are additionally available at locations in Europe, North America and Asia Pacific. KernelHost GmbH itself is headquartered in Vienna (Austria).
Is a server in Germany automatically GDPR compliant?
No. A location inside the EU means that the GDPR applies and that the stored data does not leave the EU through the location alone. Whether your processing is lawful depends on the legal basis, the purpose, your access controls and the services you pull in. You remain the controller responsible for that, and with third-party data you normally need a data processing agreement. This is not legal advice.
What latency do I get from Vienna or Munich to Frankfurt?
As rough figures from experience on a well-connected fixed line: roughly 5-8 ms round-trip time from Munich, roughly 10-15 ms from Vienna. Mobile connections and older DSL lines are clearly above that. Only your own measurement is reliable: ping or mtr against test.kernelhost.info from the line your users actually use.
Why is the datacenter in Frankfurt and not in Vienna?
With DE-CIX, Frankfurt am Main is the largest internet exchange point in Germany. The maincubes datacenter sits a few hundred metres away from it, which keeps the paths to the networks of the access providers in Germany, Austria and Switzerland short. For users in Vienna that means roughly 10-15 ms of round-trip time by experience, which is not noticeable for websites and business applications. None of that affects KernelHost GmbH, which remains headquartered in Vienna.
When should I choose a location other than Frankfurt?
When your users sit mostly outside Central Europe and the application reacts to round-trip time, game servers, voice servers or remote desktop for example. Unlimited Traffic KVM servers cover that, with the location selected in the order form, among others in London, Strasbourg, Warsaw, Helsinki, Canada, the USA, Singapore, Tokyo, Seoul, Mumbai and Sydney. For backups, batch jobs and mail servers the location hardly matters.
Is there a minimum term or a notice period?
No. All products run PrePaid: you pay for a period in advance and then decide again. There is no contract, no minimum term, no notice period and no automatic renewal unless you switch it on yourself. A server you do not renew expires at the end of the paid period.

Server location Germany Austria Latency GDPR Datacenter Frankfurt am Main Checklist