Article 28 Data Act Notice: Jurisdiction and Safeguards Against Governmental Access

Modified on Tue, 8 Sep at 3:25 PM

Article 28 Data Act Notice: Jurisdiction and Safeguards Against Governmental Access

This notice describes where Hubhus ApS hosts the Hubhus platform and how requests from third-country governments for non-personal data are handled. It supports transparency under Article 28 of Regulation (EU) 2023/2854 (the EU Data Act).

TL;DR

Hubhus runs exclusively on ICT infrastructure inside the EU (currently Curanet and Hetzner). No platform data is hosted, processed, or stored outside the EU/EEA. Third-country access requests for non-personal data must go through applicable EU legal frameworks and are assessed against EU and Danish law before any honouring of the request.

Key points in 3 steps

1

EU-only hosting

The Hubhus platform uses ICT infrastructure hosted exclusively within the EU. Current hosting suppliers are Curanet and Hetzner, both operating data centres within the EU.

2

Third-country access

Any request from a third-country government or court for access to, or transfer of, non-personal data held by Hubhus must be made through applicable EU legal frameworks (such as a mutual legal assistance treaty or an equivalent international agreement).

3

Legal assessment before disclosure

Hubhus and its hosting suppliers assess each such request against EU and Danish law before any request is honoured. They do not voluntarily transfer non-personal data to authorities outside the EU/EEA other than as required by a binding EU or Danish legal obligation.

Legal basis: EU Data Act Art. 28  ·  Hosting: EU only (Curanet, Hetzner)  ·  Last updated: 8 September 2026
Read more

Jurisdiction and infrastructure

Hubhus ApS provides the Hubhus platform using ICT infrastructure hosted exclusively within the EU. Hubhus' hosting suppliers currently include Curanet and Hetzner, both operating data centres within the EU. No platform data is currently hosted, processed, or stored outside the EU/EEA.

Because all ICT infrastructure used to provide the service is located within the EU and subject to EU and Danish law, any request from a third-country government or court for access to, or transfer of, non-personal data held by Hubhus must be made through applicable EU legal frameworks (such as a mutual legal assistance treaty or an equivalent international agreement) and is assessed by Hubhus and its hosting suppliers against EU and Danish law before any such request is honoured.

No voluntary transfer outside the EU/EEA

Hubhus and its hosting suppliers do not voluntarily transfer non-personal data to authorities outside the EU/EEA other than as required by a binding EU or Danish legal obligation.

Hosting supplier assurance

Hubhus' hosting suppliers maintain independent third-party security certifications and assurance reports (including ISO 27001 and ISAE 3402 Type 2), confirming the technical and organisational controls described above.

Common searches

Article 28 • EU Data Act • governmental access • jurisdiction • EU hosting • Curanet • Hetzner • non-personal data • MLAT • third-country request

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article