EU-hosted QR code platforms: what data residency changes for the buyer (2026)
Checked on 6 October 2026. Hosting statements were read from each vendor's own privacy policy, subprocessor list or trust page that day; legal facts are described as of that date. This is a buyer's checklist, not legal advice. Re-verified quarterly and whenever the transfer framework changes. How we compare QR platforms explains the method.

Which data does a QR code actually create?
A static code creates none: the phone reads the destination from the pattern and goes there. A dynamic code, which is every code worth managing, routes each scan through the vendor's redirect, and that hop is where data appears.
- At minimum: an IP address, a user agent string identifying the phone and browser, a timestamp and the code scanned. Under GDPR an IP address is personal data.
- Usually: a country and city derived from the IP, and a device and operating system derived from the user agent.
- On form, registration and payment codes: whatever the person types, such as a name, an email address or order details.
- On conversational codes: the questions people ask, which can contain anything.
For the scan data your codes collect, you are the controller and the QR platform acts as your processor. Where the processor's infrastructure sits decides whether an international transfer happens every time a customer in Lyon scans a poster.
GDPR compliant is not the same as EU hosted
Every platform in this comparison says it is GDPR compliant, and in the sense that matters for paperwork most of them are: a privacy policy, a data processing agreement, deletion procedures and a lawful basis for any transfer. That is a claim about how data is handled.
EU hosting is a claim about where. It means the servers that receive the scan, store the record and serve the analytics are in the European Union. It is the narrower claim, fewer vendors make it, and buyers often treat the two as one.
Where eight QR platforms say they host
| Platform | Hosting stated | Compliance stated | Transfer terms stated |
|---|---|---|---|
| QRCodeKIT | AWS EU regions, Cloudflare in front | Has been certified to ISO 9001, 27001 and 14001; GDPR; DPA available | Lawful transfer mechanisms, set out in the privacy policy |
| Hovercode | DigitalOcean, Frankfurt, Germany | GDPR; no certification of its own; DPA on request | GDPR "through EU data residency"; no mechanism named |
| ME-QR | Hetzner, Germany | GDPR; no certification | Standard Contractual Clauses; says data may be stored outside the EEA |
| Uniqode | AWS, United States | SOC 2 Type 2, HIPAA, GDPR; has been certified to ISO 27001:2022 | Data Privacy Framework or Standard Contractual Clauses |
| Bitly | Google Cloud and AWS, United States | SOC 2 Type 2, GDPR, CCPA | Data Privacy Framework and Standard Contractual Clauses |
| Scanova | AWS, Oregon, United States | SOC 2, GDPR; has been certified to ISO 27001:2022 | Standard Contractual Clauses |
| QR TIGER | AWS, "multiple countries", none named | GDPR, CCPA; has been certified to ISO 27001:2022 | Standard Contractual Clauses |
| Flowcode | Not stated | SOC 2 Type 2, HIPAA, GDPR, CCPA | Data Privacy Framework and Standard Contractual Clauses, "when applicable" |
Sources: each vendor's privacy policy, subprocessor list and trust or security page, read 6 October 2026.
Three platforms name the European Union as where they host: QRCodeKIT on AWS EU regions, and Hovercode and ME-QR in Germany. Of those three, QRCodeKIT is the only one that has been certified to ISO 27001, so an EU host and an audited information security management system come together. Uniqode, Bitly and Scanova name the United States, which is lawful with the right paperwork and is the common case. QR TIGER and Flowcode do not name a region, so for those two the hosting answer has to come from the vendor in writing.
Hosting is also not the whole answer. None of these eight platforms is headquartered in the EU, and a vendor's own staff and service providers can access data from wherever they work. That is why every privacy policy in this table, ours included, describes international transfers, and why the transfer terms belong in your file next to the hosting region.
Put it into practice
Create a dynamic QR code free and see it work. No credit card required.
Get started freeWhat the law currently says about US processing
Transfers of personal data from the EU to the United States were thrown into doubt in 2020, when the Court of Justice of the EU invalidated the Privacy Shield framework. In July 2023 the European Commission adopted the EU-US Data Privacy Framework, which restored a lawful basis for transfers to US companies that certify under it. Transfers can also rest on Standard Contractual Clauses with a transfer impact assessment.
On 3 September 2025 the EU General Court dismissed the first challenge to the framework (Latombe v Commission, T-553/23). The claimant appealed to the Court of Justice in October 2025 (C-703/25 P), and that appeal was still pending on 6 October 2026. The Court of Justice is the court that struck down both of the framework's predecessors.
Two things follow for a buyer. Using a US-hosted QR platform is lawful today with a data processing agreement, a named transfer mechanism and a record in your own register of processing. And organisations in healthcare, finance, public administration and education are often advised to prefer EU processing where a comparable service exists, or to document why they did not. That is why "where is it hosted" has moved from an IT question to a procurement one.
The five questions to put in writing
Ask each of these before signing, and keep the answers with the contract.
- In which country or region is scan data received, stored and processed, including backups and analytics?
- Which sub-processors handle the data, and where are they? Cloud provider, CDN, analytics, email, support desk, and any AI provider behind a conversational feature.
- Which transfer mechanism applies if any processing happens outside the EU: Data Privacy Framework certification, Standard Contractual Clauses, or both?
- What is retained, for how long, and can I export and delete it? Scan logs, form submissions, conversation transcripts.
- What happens to the data at contract end, and how quickly is it deleted after I leave?
A vendor that cannot answer these in writing is telling you something. Our guide to writing a QR code data retention policy covers what to do with the answers on your side.
QRCodeKIT's answers, with sources
Because this comparison is published by QRCodeKIT, its own position is stated plainly rather than implied.
- Where. The platform is hosted in the European Union on Amazon Web Services EU regions, with Cloudflare in front, server mirroring and daily backups (fact sheet).
- Transfers. The privacy policy states that certain personal data may be accessed or processed outside the EU, including in the United States, under a lawful transfer mechanism. We do not claim that data never leaves the EU, and you should be wary of any vendor that does.
- Handling. QRCodeKIT is GDPR compliant and offers a data processing agreement. Its certifications are in the table above; it does not hold SOC 2 or HIPAA.
- Your controls. Scan reports export per code as PDF or XLS. Codes can be paused, which stops both the redirect and data collection, or deleted to the trash and then deleted permanently. Cleo, the AI agent at the scan, answers from the content you load; AI QR code privacy explains what a conversational code collects.
- Paperwork. Ask [email protected] for the data processing agreement and the safeguards that apply to your data. If your requirement is EU-only processing, say so; the answer you get in writing is the one that counts.
How data residency should weigh in the decision
For most marketing uses, such as a poster, a menu or a business card, the data created is an IP address and a device string, the transfer is lawful with a DPA in place, and residency should weigh less than whether the code keeps working and whether you control the domain it points through.
For lead-form codes, registration, payments, health, education and public-sector use, residency belongs near the top of the list. Ask the five questions, get the answers in writing, and if a vendor's documents say "United States" while its sales deck says "EU", believe the documents.
One design decision reduces the exposure whichever vendor you choose: put the code on a short-link domain you own. It does not change where the redirect is processed, but if your residency requirement tightens later, you can move the redirect to another provider without reprinting. QRCodeKIT includes a custom domain on its Pro and Enterprise plans.
Frequently asked questions
Does a QR code collect personal data?
A dynamic code does, at every scan: at least an IP address, a device string and a timestamp, plus whatever a form or conversation collects. A static code collects nothing after creation, because no server sits between the code and the destination.
Is GDPR compliance the same as EU hosting?
No. GDPR compliance describes how data is handled: policies, agreements and lawful transfer mechanisms. EU hosting describes where it is processed. A vendor can be GDPR compliant while hosting in the United States, which is the common case.
Which QR code platforms are hosted in the EU?
Of the eight platforms checked on 6 October 2026, three name EU hosting: QRCodeKIT (AWS EU regions), Hovercode and ME-QR (both Germany). Uniqode, Bitly and Scanova name the United States; QR TIGER and Flowcode do not name a region.
Is QRCodeKIT hosted in the EU?
Yes. QRCodeKIT runs on Amazon Web Services EU regions with Cloudflare in front, and that is where scan records and hosted content are stored. Its privacy policy also provides for some processing outside the EU, including in the United States, under lawful transfer mechanisms, and a data processing agreement is available.
Is it legal to use a US-hosted QR platform for EU customers?
Yes, with a data processing agreement and a valid transfer mechanism such as the EU-US Data Privacy Framework or Standard Contractual Clauses, recorded in your register of processing. The framework was upheld by the EU General Court in September 2025; an appeal to the Court of Justice is pending.
What is the single most useful thing to ask a vendor?
Where scan data is received, stored and processed, including backups and analytics, and under which transfer mechanism. Get the answer in writing before you print.
Two free dynamic QR codes. Yours forever.
No credit card. No expiry. The original dynamic QR platform since 2009.





