n8n Cloud or Self-Hosted? The GDPR Decision
n8n Cloud stores data in Frankfurt/EU, self-hosted gives you full control. What this really means for GDPR.
n8n Cloud stores data for hosted plans within the EU on servers in Frankfurt, as n8n states on its own pricing page, and also offers a Data Processing Agreement (DPA) including EU Standard Contractual Clauses as part of its standard terms. Self-hosted n8n, on the other hand, gives you full control over the server location, because you choose and operate the infrastructure yourself. For German SMEs, neither option is automatically the more privacy-friendly choice: what matters is whether a DPA with a reliable provider is in place, who actually operates the servers, and where the data flows once workflows are connected to external AI services such as OpenAI or Anthropic. As of: July 2026.
Where does n8n Cloud store the data?
n8n Cloud stores data for hosted plans within the EU on servers in Frankfurt. n8n states this directly on its pricing page: "For hosted plans, data is stored within the EU — on servers located in Frankfurt, Germany." For companies that do not want to operate their own infrastructure for reasons of convenience or a lack of IT resources, this is a relevant starting point, because data processing then generally takes place within the EU and not in third countries. It is nevertheless important to check the current information on the hosting location directly with n8n, as infrastructure details can change.
What does the Data Processing Agreement with n8n Cloud regulate?
n8n offers a Data Processing Agreement (DPA) as part of its standard Terms of Service, which includes the EU Standard Contractual Clauses. According to the n8n documentation on privacy and security n8n, as a data processor, implements policies and practices intended to safeguard personal data on the platform. Customers can additionally countersign the DPA independently via a form provided by n8n, as described on the n8n Data Processing Agreement page. The list of sub-processors, meaning other service providers that n8n uses to operate the cloud, can be viewed separately at n8n.io/legal/sub-processors/. This article is not a substitute for legal advice: whether the DPA is sufficient for your specific use case should be clarified with your data protection officer or a law firm.
What does self-hosted mean for server location and control?
With self-hosted n8n, you decide yourself where and with which provider the server is located, for example with a German hosting provider with a data center in Germany. This gives you the greatest possible control over data residency, because no data has to leave the data center you have chosen. In return, you are responsible yourself for operation, updates, encryption, and access protection of the instance. For the retention of execution data, n8n provides the environment variable EXECUTIONS_DATA_MAX_AGE for self-hosted instances, which allows old execution data to be deleted automatically, which, according to the n8n documentation makes handling deletion requests easier. With n8n Cloud, on the other hand, workflow code and credentials are stored indefinitely until you delete them or cancel the account.
Why is the data flow to AI APIs a separate topic?
Regardless of whether n8n runs in the cloud or self-hosted, the data flow to connected AI services is a separate topic that has nothing to do with n8n hosting itself. As soon as a workflow sends data to OpenAI, Anthropic, or another external AI provider, that provider's own processing terms, server locations, and, where applicable, its own DPAs apply, regardless of whether n8n itself runs in Frankfurt or on your own server. Anyone sending personal data through an AI node should therefore check individually for each connected service where the processing takes place and whether a suitable DPA is in place. We include this check at NordFlux as standard in automation projects, because it is often overlooked in practice.
Frequently asked questions about n8n Cloud vs. self-hosted
Is n8n Cloud GDPR-compliant?
With the server location in Frankfurt and a DPA including EU Standard Contractual Clauses, n8n Cloud offers important prerequisites for data-protection-compliant use. Whether this is sufficient for your specific use case depends on what data you process and how you use n8n, which is why a blanket classification as "GDPR-compliant" is not seriously possible without a legal review. This text is not legal advice.
Is self-hosted n8n automatically more privacy-friendly than n8n Cloud?
No, not automatically. Self-hosted shifts the responsibility for server location, encryption, backups, and security updates entirely to you, and misconfiguration can create just as many data protection problems as a cloud solution. The advantage lies primarily in control, not automatically in the level of protection.
Do I need a separate DPA for AI connections in n8n?
Yes, generally you do. The DPA with n8n only covers processing by n8n itself, regardless of whether you use Cloud or self-hosted. As soon as a workflow sends personal data to OpenAI, Anthropic, or another external API, you need a separate contractual basis with that provider for this.
How long does n8n Cloud store my workflow data?
According to n8n documentation, n8n Cloud stores workflow code and credentials indefinitely until you delete them or cancel your account. For self-hosted instances, you can use the environment variable EXECUTIONS_DATA_MAX_AGE to specify that execution data is automatically deleted after a certain time.
NordFlux UG (haftungsbeschränkt)
NordFlux builds digital employees for organisations: automations and AI agents that take over repetitive work. You stay in control.
Concrete questions about automation or AI?
In a free initial analysis we discuss your case directly. No strings attached.