Skip to content
Glossary

Data residency answers where, not who

Residency says which datacentre holds the bytes. It does not say which legal system can compel their disclosure, and a review that stops at residency has answered the easier of the two questions.

What a buyer is really asking when they ask about residency

Will this survive our data protection review?
Residency is one input. The review will also want a processing agreement, a sub-processor list, the technical and organisational measures, and a retention period. Location alone has never been sufficient for any of those.
Can a foreign authority compel access to our data?
This is the question residency does not answer. Compulsion follows the entity, not the building: a provider incorporated in a jurisdiction is reachable by that jurisdiction regardless of which region the data sits in.
Where does the model see our data?
Increasingly the real gap. Application data may be EU-resident while prompts and page content travel to an inference endpoint elsewhere, which is the residency question people forget to ask a second time.
How long is any of this kept?
Retention often matters more than location. Data that is deleted after a day has a small exposure wherever it lived; data kept indefinitely has a large one even in a favourable jurisdiction.

Four terms that are not synonyms

What it promises What it does not
Data residency Storage and processing in a stated region Anything about who can compel disclosure
Data localisation A legal duty to keep data in-country That the operator is domestic
Data sovereignty Subject to one jurisdiction's law A specific technical architecture
Operational sovereignty Only in-region staff can access it That the parent company is in-region
Encryption at rest Protection against a stolen disk Protection against the key holder
A region dropdown Compute located where you chose Any change to the operator's jurisdiction

As of 2026-08-31 · Competitor details come from each vendor's published pricing page on that date.

Common questions

Is EU-hosted the same as EU-sovereign?

No, and the distinction is the entire content of most European procurement conversations. EU-hosted describes where the servers are. EU-sovereign describes which law reaches the company operating them, and only the second is settled by looking at the vendor rather than the region menu.

Does encryption make residency irrelevant?

Only if the provider genuinely cannot decrypt, which is rare for anything that has to process the data rather than merely store it. A browser has to render the page, which means the content is in cleartext in memory somewhere, and that somewhere has a jurisdiction.

What should a questionnaire actually ask?

Where compute runs, where each store sits, where the encryption keys live, who can access them, which sub-processors are involved and where they are, how long each artefact is retained, and where model inference happens. Seven questions, and the last one is the newest and most often skipped.

Does GDPR require EU residency?

Not directly. It regulates transfers rather than mandating location, and lawful transfer mechanisms exist. Residency is a way of making the transfer question disappear rather than a legal requirement, which is why it is a commercial argument more than a compliance one.

Bring the questionnaire

Most evaluations start with a data protection review. We would rather answer yours early than late.