PostHog gives you the processor-side contract GDPR asks for and something most analytics vendors do not: a genuine choice about where your data lives. You can run PostHog Cloud in Germany, in the United States, or host it yourself. Its subprocessor list is four entries long. Whether your analytics are lawful still depends on what you collect and on what basis, which is the part no deployment choice settles.
This article covers how the three deployment options change the legal picture, where the DPA is and how to get one, what the subprocessor list actually says, the capture controls worth setting, and what choosing Frankfurt does not do for you.
Three Deployment Choices, And They Change The Question
Most vendors in this category offer one architecture and a contract to paper over it. PostHog offers three.
PostHog Cloud EU runs on AWS in eu-central-1, Frankfurt. PostHog describes it as an entirely independent instance, with event data, user data and the product itself hosted on EU infrastructure, and answers the question of what is transferred from the EU to the US with a single word: none. PostHog Cloud US runs on AWS us-east-1 in Virginia. And PostHog remains self-hostable, which puts the data wherever you put it.
That matters because the hardest part of most vendor assessments is the transfer analysis, and choosing the EU region removes it rather than papering over it. Where a transfer is required from the UK, EU or EEA to PostHog's US environment, PostHog states it relies on EU Standard Contractual Clauses — but if you never make that transfer, you are not relying on anything.
Two practical notes. The regions are separate instances, so this is a decision made at setup rather than a toggle you flip later. And self-hosting moves the entire compliance burden onto you: no processor to point at, no DPA to file, and every technical and organisational measure your responsibility.
Where The DPA Is, And How To Get One
PostHog's security handbook states that it enters into data processing agreements with PostHog Cloud customers on request, links a generator for producing one, and confirms it maintains a register of every DPA it has entered into.
Note the shape of that: on request, rather than incorporated automatically. If nobody at your company has asked, you may not have one, and "we use their cloud product" is not the same as having an Article 28 contract in place. Check before a customer asks you to prove it. If you are unclear what the contract needs to contain, our guide to data processing agreements covers the required elements.
PostHog also publishes that it has assigned a data protection officer, takes privacy questions at a published address, and keeps a data processing register available to any interested party on request. Registering as a service provider rather than a controller under CCPA is stated separately. We checked these pages on 7 August 2026.
A Subprocessor List You Can Actually Read
This is the part worth showing your security reviewer. PostHog's subprocessor page, last updated 10 March 2026 when we checked, lists four entries: Amazon Web Services for cloud storage, Wiz for security vulnerability management, PlanetScale for database operations and performance monitoring, and Modal Labs for serverless compute used in isolated code execution.
Each row carries the processing location, and the locations track your region choice: US for PostHog US Cloud, Germany for PostHog EU Cloud, with the security vendor operating in Germany and France. PostHog describes keeping the list to a strict minimum, and four entries is a claim that survives contact with the page.
Four is unusual enough to be a competitive fact. When you publish your own subprocessor list — and if you process on behalf of business customers you should — a short, well-located chain is easier to defend than a long one. Our guide to subprocessors under GDPR covers what belongs on yours.
PostHog states that it posts updates to the page and gives notice in accordance with the DPA terms. Read your executed DPA for the notice period rather than assuming one.
What PostHog Captures, And What You Can Turn Off
PostHog's own framing is that product analytics does not require personal data to work, and that it provides controls for customers who want to minimise collection from end users.
That framing is fair but it is an invitation, not a default. PostHog's product spans insights, heatmaps, session recording and feature flags, and session recording in particular captures what happens on the page — which is where personal data arrives without anyone deciding to collect it — an email address rendered in an account header, an order reference, a support message. Masking configuration is the control, and it is applied deliberately rather than inherited.
Whether recording sessions is lawful at all, and on what basis, is a separate question from whether PostHog is configured well. Our guide to session replay under GDPR covers that analysis.
What Choosing Frankfurt Does Not Do
PostHog says this itself, plainly, and it is the most useful sentence on their site: deploying PostHog Cloud EU is not enough on its own. You still need a basis for the processing, and you still need to satisfy every other provision — including erasure.
So the EU region resolves the transfer question and nothing else. It does not establish a lawful basis for analytics. It does not obtain consent where consent is required. It does not set your retention period, identify a person across your events, or delete them on request. And it does not decide whether the identifiers you attach to events turn pseudonymous analytics into a directly identifiable profile, which is a decision you make the first time you call an identify method with an email address.
Common Mistakes With PostHog And GDPR
Assuming a DPA exists because you use the product. PostHog enters DPAs with Cloud customers on request. If nobody asked, check — an unrequested DPA is an absent one.
Treating the EU region as compliance. It settles where data rests. It says nothing about your lawful basis, your retention or your erasure path, and PostHog says so on its own site.
Choosing the region late. The clouds are separate instances. Decide before you have a year of events in the wrong one.
Identifying users out of habit. Attaching an email address to every event converts an analytics dataset into a personal-data store with your name on it. Decide whether you need the identifier before you send it.
Forgetting that self-hosting removes the processor. Running it yourself is a legitimate answer to the transfer question and a complete transfer of responsibility. There is no vendor to name and no security measures but yours.
FAQ
Does PostHog offer EU data residency?
Yes. PostHog Cloud EU runs on AWS in Frankfurt, Germany, and PostHog describes it as an entirely independent instance where the data and the product are hosted on EU infrastructure. PostHog Cloud US runs in Virginia. The regions are separate instances, so the choice is made at setup rather than switched later.
Do I need to sign a DPA with PostHog?
PostHog states that it enters into data processing agreements with PostHog Cloud customers when requested, and provides a generator for producing one. Unlike vendors who incorporate the terms automatically, this is opt-in — so confirm one is actually in place rather than assuming it came with the account.
Who are PostHog's subprocessors?
Its published list names four: Amazon Web Services for cloud storage, Wiz for security vulnerability management, PlanetScale for database operations monitoring, and Modal Labs for serverless compute. Processing locations follow your region choice, with the US for PostHog US Cloud and Germany for PostHog EU Cloud.
Does using the EU region make my analytics GDPR compliant?
No, and PostHog says so directly. Deploying in the EU addresses where data is stored and processed. You still need a lawful basis, consent where consent is required, a retention period, and a working process for erasure and other data subject rights.
Closing Thought
There is something clarifying about a vendor that tells you their product will not make you compliant. Most marketing pages in this category work hard to leave the opposite impression, and the result is teams who believe a procurement decision discharged a legal obligation.
The choice PostHog offers is real and worth taking seriously — few vendors let you remove the transfer question entirely. But it removes one question out of six, and the other five are about what you collect, why, for how long, and what happens when someone asks you to stop. ComplyDog gives you a compliance portal on your own domain covering your DPA, your subprocessor list, your data subject request intake and your security page. It will not configure your masking rules. It will mean that the answers you worked out once are somewhere a customer can read them.