Otherwise I fail to see why Finland makes sense, unless you need cheaper energy for applications that don't need low latency.
We host our cloud instances in our own data centers in Nuremberg and Falkenstein. And we operate our data centers in accordance with ISO 27001 guidelines while also adhering to strict German data protection regulations.This ( http://eur-lex.europa.eu/eli/reg/2016/679/oj ) replaces all data proyection laws in the EU.
Must comply now, but sanctions won't be in effect until may 25th.
That is not technically correct, and the difference matters.
The EU regulation forces it's members to implement their own local laws in alignment to the EU regulation. The EU regulation can get a member state into trouble if not implemented in time or correctly. They describe a set of "baseline" data protection laws for the whole EU, but the members can still have stronger local rules. Only the local law is what can get a resident company in trouble.
Germany has (had for a long time) very strong data protection laws that are still going to be stronger than the EU regulation.
* By "comes in", I mean begins being enforced. There's been a 2 year grace period as advance notice.