Skip to content

EU data residency for infrastructure: a practical checklist

Customers, regulators and procurement teams increasingly ask one question: where is our data, and who can reach it? This checklist turns that question into concrete infrastructure decisions and the paperwork that proves them.

7 minute read

Residency is more than a region setting

Choosing an EU region on a hyperscaler keeps the primary data in the EU, but backups, logs, support access, metadata and the provider's own sub-processors may not be. For many customers and for data protection authorities, the legal reach of a non-EU parent company over the provider is itself the problem.

A defensible residency position needs the data, its copies, the people who can access it and the legal entity responsible for it all to be in the EU.

The checklist

  1. Primary data: which data centre, which country, which legal entity operates it?
  2. Backups: where are they stored, and are they encrypted with keys held in the EU?
  3. Logs and telemetry: where do metrics and logs go, and for how long?
  4. Administrative access: who can log into the systems, from where, and is every access logged?
  5. Support: when you open a ticket, which country does the engineer sit in?
  6. Sub-processors: is there a complete list, with locations, and do you get notice of changes?
  7. Data processing agreement: signed, with standard EU terms, naming the controller and processor roles?
  8. Deletion: what happens to data and backups when the contract ends, and how long until it is gone?
  9. Incident notification: what is the commitment, in hours, for telling you about a breach?
  10. Evidence: can the provider produce the change log, access log and restore reports for an audit?

Encryption and key custody

Encryption at rest on the provider's keys protects against a stolen disk, not against the provider. Residency arguments are stronger when backups are encrypted with keys you or an EU-only processor hold, and when the key is stored separately from the data.

The documents you will be asked for

  • A data processing agreement with the processor's obligations, sub-processor list and location commitments.
  • A security overview describing hardening, access control, logging, patching and backup practices.
  • Evidence of controls: audit log exports, vulnerability scan summaries, restore test reports, incident write-ups.
  • A hardware and location inventory for the systems processing the data.
  • Certifications where relevant: ISO 27001 for the data centre operator at minimum.

Sector notes

  • Financial services: DORA expects ICT third-party risk management, exit strategies and incident reporting; keep the inventory and the exit plan current.
  • Health: national rules often add explicit location requirements; check them before choosing a country.
  • Public sector: procurement frequently excludes providers subject to non-EU surveillance law; a European legal entity is often a hard requirement.
  • Any sector: your customers' own residency promises flow down to you. Read their contracts.

What residency does not solve

Residency is about location and control. It does not make an application secure, a backup tested or an access policy sensible. Treat it as one control in a set, and expect the auditor to ask about the others in the same meeting.

Tell us what you run. We will tell you what it costs to run it properly.

A quote within one business day, from an engineer rather than a sales script. No setup fee, three-month minimum, delivery in 48 hours.