Does your website cross European data boundaries?

Find out which countries your website connects to — servers and third-party services.

https://

How the scan works

We load your homepage, list every service it connects to, and map each one to a country.

  1. Open

    Load the homepage like a visitor

  2. Collect

    List every script and service the page loads

  3. Map

    Match IPs to countries and domains to companies

  4. Show

    Flag connections outside the EU/EEA

What are European data boundaries?

When someone opens your site, their browser talks to every third party you loaded. Analytics, ads, chat widgets and tag managers typically receive an IP address, cookies and other identifiers. Under EU law that is personal data — and sending it outside the EEA is a restricted transfer.

  • It is the visitor's data

    The GDPR protects people in the EU, not servers. An IP address, a cookie ID or a device fingerprint is already personal data. You do not need a name or an account.

  • Third parties receive it automatically

    Scripts you did not write still collect. Analytics, advertising, session replay and support tools send visitor data to whoever hosts them — often a company outside the EEA.

  • Leaving the EEA needs a legal basis

    A transfer outside the EEA requires safeguards: an adequacy decision, standard contractual clauses, or another recognised ground. Without one, the transfer can be unlawful — and you remain responsible as the site operator.

Official sources

Frequently asked questions

Quick answers about what the scan shows and why it matters.

What does “crossing European data boundaries” mean?

When a website loads, it connects to servers and third-party services around the world. When any of those servers or services sits outside the EU/EEA, your site — and the data it handles — crosses a European data boundary. DataBoundary.eu loads your homepage and maps each connection to a country so you can see where your data actually goes.

Why does it matter for my website?

Under the GDPR (Regulation (EU) 2016/679, Chapter V) and the Court of Justice’s Schrems II ruling, sending personal data outside the EU/EEA carries legal obligations — adequate safeguards, valid transfer mechanisms, and a risk assessment. Most site owners have no idea which countries their hosting, CDN, fonts, and analytics connect to. A scan is a quick first step to finding out.

Do CDNs like Cloudflare or AWS CloudFront count?

Yes. A CDN serves your site from edge servers in many countries and can keep content outside the EU/EEA. DataBoundary.eu lists the CDN as a connection and maps where its servers are observed, so a CDN in your stack does not hide where your visitors actually connect.

What about Google Fonts, analytics, or tag managers?

They count too. These are third-party services your homepage references, and they often connect to servers outside Europe. The scan lists every third-party connection it can detect on the homepage — not just your own infrastructure — and maps each one to a country.

Is DataBoundary.eu a security scanner?

No. It only reads the public homepage you submit, follows a limited redirect chain, and performs public DNS lookups. It never submits forms, logs in, tests vulnerabilities, or accesses private networks. Site owners can block DataBoundaryBot in robots.txt at any time.

How accurate is the result?

The scan is based on public signals — the page’s own references and public DNS records — so it is a strong first-pass indicator, not a legal opinion or proof of where data is stored. Use it as a starting point to review your infrastructure and third-party providers.