You're in the ACP Group Bitrix24 Knowledge Base Main site acp-24.com →
ACP Group ACP Group Bitrix24 Gold Partner Knowledge Base
EN PT
+971 55 780 1481
Pricing & Comparisons

GDPR-Compliant CRM: Why Self-Hosted Bitrix24 Wins for EU Companies

Published: ·By Yurii Dobrovolsky, Bitrix24 Implementation Specialist·Updated: ·9 min read

For companies subject to GDPR in the European Union or similar data protection regulations globally, self-hosted Bitrix24 (on-premise) offers the only reliable path to full control over where customer data is stored - something no public cloud provider can guarantee by contract.

Yurii Dobrovolsky, Bitrix24 Implementation Specialist · ACP Group. Shares hands-on experience from similar Bitrix24 (Alaio) projects delivered at ACP Group.

The Core Problem: Where Does Your CRM Data Actually Live?

For DPOs and IT directors operating under data protection regulations, the cloud version of Bitrix24 (Alaio) represents a concrete compliance risk: customer data may transit through servers across multiple jurisdictions beyond the controller's oversight, while the self-hosted version ensures everything runs exclusively on the company's own infrastructure.

When a business uses a public cloud CRM, it delegates a critical decision to the vendor: in which country, in which datacenter, and under which laws will its customer data be processed. For DPOs and IT directors subject to modern privacy legislation, that uncertainty is precisely the kind of risk these laws were designed to eliminate.

With the Bitrix24 cloud version, data can transit through third-party servers across different jurisdictions. In internal projects reviewed by ACP Group, we identified architectures where data from forms, emails, and approvals flowed through external provider servers - sometimes in countries without equivalent data protection agreements. That diffuse data flow is the opposite of what modern privacy law requires.

With the self-hosted (on-premise) version, Bitrix24 runs entirely on infrastructure that your company controls - whether that is your own hardware, a private cloud, or an IaaS provider of your choice. No data is transferred to the vendor's servers.

What Data Protection Laws Require Regarding Data Residency

Modern data protection regulations converge on practical requirements that make a self-hosted CRM the safer choice: both impose a mandatory legal basis for processing, restrict international transfers to jurisdictions with an adequate level of protection, and place full accountability on the controller - requirements that are far easier to meet when data remains on your own server.

These regulations align on several practical points that directly affect CRM selection:

Requirement LGPD (Brazil) GDPR (EU)
Legal basis for processing Mandatory (art. 7) Mandatory (art. 6)
International data transfers Only to countries with adequate level or contractual clauses Only to countries with adequacy decision or SCCs
Right to erasure Yes (art. 18) Yes (art. 17)
Record of processing activities Recommended by ANPD Mandatory (art. 30)
Controller accountability Full Full

When the CRM is hosted in a public cloud, meeting these requirements depends on the vendor's terms - which can change. When it runs on your own server, it depends on your internal policies.

Why the Self-Hosted Version Solves What Cloud Cannot

Bitrix24 self-hosted gives the data controller complete authority over physical location, infrastructure access, backups, permissions, and network security - and a full base deployment, including SSL configuration and compliance settings, is completed in approximately 7 hours of technical work.

The on-premise version of Bitrix24 places the following elements directly in the hands of the data controller - your company:

  • Physical data location: the server can be installed in a certified datacenter in the jurisdiction of your choice, guaranteeing data residency by design
  • Infrastructure access: your IT team has root SSH access to the server; no vendor employee accesses the data without explicit authorization
  • Backup configuration: backups are configured for local storage or a private repository, with no dependency on vendor systems
  • Granular access control: user roles and permissions by individual, segment, or department are fully configurable with complete auditability
  • SSL and network security: SSL certificates (including Let's Encrypt), firewalls, and open ports are defined by the internal team

In cloud-to-on-premise migration projects conducted by ACP Group, the base deployment of the self-hosted version - including SSL configuration, Push & Pull for chats, automatic backups, and removal of test data - typically takes approximately 7 hours of technical work.

Data Flow: Public Cloud vs. Self-Hosted

In a public cloud model, lead and form data transits through external datacenters of variable jurisdiction before reaching the CRM, while in the self-hosted model the entire flow remains within the company's controlled perimeter, with the DPO having direct access to the infrastructure.

There is a fundamental structural difference between the two architectures. In a public cloud, customer data, form submissions, and emails pass through multiple external points before reaching the CRM. In a self-hosted setup, the entire flow stays within the company's controlled perimeter.

flowchart LR
    A[Formulário Web / Lead] --> B{Modelo de Implantação}
    B -->|Nuvem Pública| C[Servidores do Fornecedor]
    C --> D[Datacenter externo - jurisdição variável]
    D --> E[CRM Cloud]
    B -->|Self-Hosted| F[Servidor Próprio / IaaS privado]
    F --> G[Datacenter no Brasil ou UE]
    G --> H[Bitrix24 On-Premise]
    H --> I[DBA / DPO com acesso total]
    E --> J[DPO sem acesso direto à infra]

Access Control and Audit Trail

Bitrix24 self-hosted allows you to configure role-based access segmented by function, restrict contact visibility, and automate assignment of record owners - ensuring that only the right people access each piece of personal data, with the full auditability required by data protection regulations, at no additional licensing cost.

Regulatory compliance is not only about where data is stored - it is about who accesses what, and when. Bitrix24 self-hosted allows you to configure:

  • Segmented user roles: managers see only their own leads; supervisors see the team pipeline; administrators have full access - all governed by rules, not manual exceptions
  • Contact base access restrictions: contact visibility limited by role, preventing unnecessary exposure of personal data
  • Automatic record assignment: automated assignment rules reduce the number of people who access each record

In typical ACP Group projects, full role and permission configuration for teams of 25 to 100 users is delivered as part of the standard implementation scope, with no additional licensing costs.

For companies that need to integrate corporate authentication, the on-premise version supports Active Directory, LDAP, and SSO - which significantly simplifies identity governance during compliance audits.

Infrastructure: Minimum Requirements and Scalability

Bitrix24 self-hosted operates from 4 cores and 12 GB of RAM for up to 50 users, scales to dedicated clusters with 64 GB or more above 100 users, and supports high-availability architecture - ensuring the operational stability that regulated organizations require during audits and data subject rights exercises.

Compliance demands stability. A system that goes down during an audit or a data access request creates legal risk. For Bitrix24 self-hosted, hardware requirements are clearly defined:

Scale CPU RAM Storage
Up to 50 users 4 cores (e.g. Intel Xeon E3) 12 GB DDR4 128 GB SSD (DB + files)
51-100 users 6-8 cores 24-32 GB DDR4 256 GB SSD + expansion
100-1,000 users Dedicated cluster 64 GB+ SAN / distributed storage

For detailed sizing by user range, refer to the hardware sizing guide for Bitrix24 self-hosted.

High-availability environments - required by business continuity policies in regulated organizations - are covered by the Bitrix24 self-hosted master-replica cluster architecture.

Migrating from Cloud to Self-Hosted: What to Expect

Migration from Bitrix24 Cloud to on-premise follows 5 structured stages - provisioning, deployment (~7h), data migration, functional validation, and post-migration support - allowing organizations to meet DPO requirements, external auditor demands, or sensitive client contract obligations without operational disruption.

Many organizations already use Bitrix24 Cloud and need to migrate to on-premise due to a DPO requirement, an external audit finding, or a new contract with a privacy-sensitive client. The process follows well-defined stages:

  1. Server provisioning - definition of technical requirements, OS, network, and DNS
  2. Bitrix24 on-premise deployment - installation, license registration, initial configuration (~7h)
  3. Data migration - transfer of CRM records, tasks, documents, settings, and integrations
  4. Functional validation - the client confirms that everything operates as it did in the cloud
  5. Post-migration support - a warranty period for adjustments

The complete migration process, including support, is detailed in the article on migrating from Bitrix24 Cloud to self-hosted.

Total Cost and the Regulatory Case

In a 3-year TCO comparison, Bitrix24 self-hosted frequently delivers a lower total cost for organizations with 50 or more users - and eliminates the risk of regulatory fines, making it a documentable compliance position before any auditor.

The most common argument against self-hosted is cost. In practice, when comparing 3-year TCO - including annual licensing, infrastructure, and renewals - the on-premise version frequently results in a lower total cost, particularly for organizations with 50 or more users. See the full cloud vs. self-hosted TCO analysis.

Beyond the financial cost, there is the regulatory cost of not being compliant:

  • GDPR fines reach up to 4% of global annual turnover or €20 million
  • Reputational damage and loss of contracts with clients who require a proper Data Processing Agreement (DPA)

Self-hosted is not merely a technical choice - it is a documentable regulatory position. When a DPO needs to demonstrate to a regulator that the company has full control over customer data, a company-owned server with an auditable backup policy (backup and disaster recovery strategy) is a far stronger argument than a public cloud SLA.


Work with a partner on your self-hosted setup. Want the control of Bitrix24 self-hosted without managing the server yourself? ACP Group deploys and operates it for you - see managed Bitrix24 self-hosted, support and maintenance plans, or request a turnkey quote.

Frequently asked questions

Does self-hosted Bitrix24 guarantee automatic GDPR compliance?

There is no such thing as automatic compliance - regulations require policies, processes, and documentation, not just technology. What self-hosted deployment guarantees is that you control where the data resides, who accesses it, and how it is protected. This significantly simplifies meeting your obligations as a data controller.

Can I host Bitrix24 on-premise on a cloud provider such as AWS or Azure?

Yes. Self-hosted Bitrix24 can be installed on any Linux server, including AWS EC2 instances, Azure VMs, or Google Cloud - provided you select the appropriate region (EU or your required jurisdiction) and retain control of the infrastructure. The key requirement is that data never passes through Bitrix24's own vendor systems.

What is the practical difference between self-hosted and cloud for a DPO?

With self-hosted, the DPO can directly audit the server, configure access logs, define retention policies, and demonstrate to regulators that data has never left the designated jurisdiction. With a cloud deployment, these guarantees depend on the vendor's contract terms - which can change and offer limited visibility.

How long does the initial self-hosted Bitrix24 deployment take?

Based on our project experience, the core technical deployment - including installation, SSL configuration, backups, and Push & Pull setup - takes approximately 7 hours. A full implementation covering data migration and CRM configuration typically ranges from 3 to 7 weeks, depending on complexity.

Does self-hosted Bitrix24 support legally valid electronic signatures and digital documents?

Yes. The on-premise version includes document management modules and can be integrated with certified electronic signature services that comply with applicable local regulations - such as eIDAS in the EU. Configuration requires defining approval workflows and document templates within the self-hosted environment.

Is it possible to migrate from Bitrix24 Cloud to self-hosted without losing data?

Yes. There is a structured migration process covering CRM records, tasks, documents, and system configurations. The client validates full functionality before the cloud environment is decommissioned, and a post-migration support period is included to handle any required adjustments.

Based on real practice

This article is based on 7 internal documents from ACP Group's practice - work plans, specifications and Bitrix24 implementation cases.

Need help with Bitrix24?

ACP Group is a Bitrix24 Gold Partner. We'll review your task, estimate the effort in hours and propose a plan - free of charge.

Didn't find your answer?

Ask a Bitrix24 expert

We'll run a demo, gather requirements and estimate your project in hours. First consultation is free.

+971 55 780 1481