EU data residency for infrastructure: a practical checklist
Customers, regulators and procurement teams increasingly ask one question: where is our data, and who can reach it? This checklist turns that question into concrete infrastructure decisions and the paperwork that proves them.
7 minute read
Residency is more than a region setting
Choosing an EU region on a hyperscaler keeps the primary data in the EU, but backups, logs, support access, metadata and the provider's own sub-processors may not be. For many customers and for data protection authorities, the legal reach of a non-EU parent company over the provider is itself the problem.
A defensible residency position needs the data, its copies, the people who can access it and the legal entity responsible for it all to be in the EU.
The checklist
- Primary data: which data centre, which country, which legal entity operates it?
- Backups: where are they stored, and are they encrypted with keys held in the EU?
- Logs and telemetry: where do metrics and logs go, and for how long?
- Administrative access: who can log into the systems, from where, and is every access logged?
- Support: when you open a ticket, which country does the engineer sit in?
- Sub-processors: is there a complete list, with locations, and do you get notice of changes?
- Data processing agreement: signed, with standard EU terms, naming the controller and processor roles?
- Deletion: what happens to data and backups when the contract ends, and how long until it is gone?
- Incident notification: what is the commitment, in hours, for telling you about a breach?
- Evidence: can the provider produce the change log, access log and restore reports for an audit?
Encryption and key custody
Encryption at rest on the provider's keys protects against a stolen disk, not against the provider. Residency arguments are stronger when backups are encrypted with keys you or an EU-only processor hold, and when the key is stored separately from the data.
The documents you will be asked for
- A data processing agreement with the processor's obligations, sub-processor list and location commitments.
- A security overview describing hardening, access control, logging, patching and backup practices.
- Evidence of controls: audit log exports, vulnerability scan summaries, restore test reports, incident write-ups.
- A hardware and location inventory for the systems processing the data.
- Certifications where relevant: ISO 27001 for the data centre operator at minimum.
Sector notes
- Financial services: DORA expects ICT third-party risk management, exit strategies and incident reporting; keep the inventory and the exit plan current.
- Health: national rules often add explicit location requirements; check them before choosing a country.
- Public sector: procurement frequently excludes providers subject to non-EU surveillance law; a European legal entity is often a hard requirement.
- Any sector: your customers' own residency promises flow down to you. Read their contracts.
What residency does not solve
Residency is about location and control. It does not make an application secure, a backup tested or an access policy sensible. Treat it as one control in a set, and expect the auditor to ask about the others in the same meeting.
Packages mentioned.
- Enterprise 48Enterprise
Core 48 compute in an enterprise chassis with redundant power and four hot-swap NVMe bays.
- CPU
- 48 cores / 96 threads
- Memory
- 256 GB DDR5 ECC
- Storage
- 4 × 3.84 TB NVMe (hot-swap)
€3,860per month - Cluster 3Cluster
Three 48-core nodes on a private network with highly available Kubernetes and Postgres.
- CPU
- 144 cores / 288 threads total
- Memory
- 384 GB DDR5 ECC total
- Storage
- 6 × 1.92 TB NVMe total
€9,850per month
Keep reading.
Backups that restore: a 3-2-1 plan for dedicated servers
How to design, encrypt, schedule and, above all, test backups for dedicated servers so the first restore is not during an outage.
Read the guideWhat it takes to run a wholesale dedicated server in production
The checklist a competent operations engineer works through between receiving a root password and trusting a dedicated server with production traffic.
Read the guideTell us what you run. We will tell you what it costs to run it properly.
A quote within one business day, from an engineer rather than a sales script. No setup fee, three-month minimum, delivery in 48 hours.