Abstract editorial illustration in coral and off-white for the topic: Data residency: where your deal data actually lives
Security

Data residency: where your deal data actually lives

  • data residency
  • data sovereignty
  • gdpr
  • security
  • compliance
  • virtual data room
Summarize with AI ChatGPTClaudePerplexityGrok
On this page
  1. The fast version, in eight lines
  2. Point 1: Data residency is where your files physically sit
  3. A document does not carry its home law with it
  4. Why the location toggle is legally loaded
  5. Point 2: Location matters because it decides who can reach your data
  6. Why 137 is the number that changed everything
  7. The fine is bigger than €20 million
  8. Point 3: Residency, sovereignty, and localization are three different words
  9. Residency is a choice
  10. Sovereignty is the consequence
  11. Localization removes the choice
  12. Why the vocabulary is not academic
  13. Point 4: A handful of laws draw the boundaries
  14. The GDPR conditions, it does not ban
  15. UK GDPR runs a close parallel
  16. US law can follow the provider, not the server
  17. Sector rules can force local storage
  18. National statutes keep multiplying
  19. Point 5: A US-hosted room can hold EU data, but not by default
  20. The cleaner route is to keep the data in the EU
  21. Point 6: The CLOUD Act is why European buyers ask who owns the provider
  22. Why sophisticated counterparties ask a second question
  23. The mitigations that exist for the sensitive cases
  24. Point 7: Getting residency wrong is a quiet failure, not a loud one
  25. The diligence stall
  26. The regulatory exposure
  27. The broken promise
  28. The part teams always underestimate: re-hosting
  29. Point 8: Choose the region by working from the strictest law
  30. Point 9: Verify residency claims the way you verify any security claim
  31. Ask where backups live, not just the primary store
  32. Get the sub-processor list
  33. Confirm the region is contractual
  34. Match it to the certifications
  35. Point 10: Most providers now offer a menu of regions
  36. Per-room beats account-wide
  37. Watch for the edges of the menu
  38. Point 11: Residency touches pricing and performance only lightly
  39. On pricing, expect a modest effect
  40. On performance, the difference is negligible
  41. Point 12: A short residency checklist to keep on hand

A European seller, an American buyer, a folder of confidential files. Before anyone argues about price, a quieter question sits in the room: on whose soil will those files live?

Encryption gets the headlines. Geography decides the law.

This guide walks the whole subject as a checklist you can scan, from the one-line definition to the region call you make at setup. Read it top to bottom, or jump to the heading you need. Everything here is orientation, not legal advice.

The fast version, in eight lines

If you read nothing else, read this.

  • Residency is a place, not a setting. It is the country the server sits in, full stop.
  • Location fixes the law. Whichever country hosts your files can, in principle, reach them.
  • The GDPR does not ban leaving the EU. It conditions it with transfer safeguards.
  • A US provider carries US legal reach abroad. That is the CLOUD Act, and it surprises people.
  • Backups count. Data in Frankfurt with copies in Virginia is not really in Europe.
  • Region choice belongs at setup. Fixing it mid-deal means re-hosting a live room.
  • Get it in writing. A dashboard toggle is not a contract.
  • Match the region to the strictest law on your files. Everything looser is then covered.

Now the detail, one point at a time.

Point 1: Data residency is where your files physically sit

Data residency is the specific country or region where a virtual data room stores and processes your files. That is the entire definition.

It is a geographic fact about the servers. Not a feature of the software, and not the same thing as encryption or access control.

When a provider tells you a room is hosted in Frankfurt, London, or Virginia, that location is your data residency. It sets the primary legal regime for every document inside the room.

A document does not carry its home law with it

Here is the mental model people miss. A file does not travel with the law of the country where it was created.

Once your files land on a server, they fall under the laws of the country that server sits in. That applies on top of any law already governing the deal.

For a purely domestic transaction, this rarely matters. For anything that crosses a border, and most modern deals do, residency becomes the hinge that compliance turns on.

Why the location toggle is legally loaded

That small region drop-down in a provider’s setup screen is easy to skip past.

Do not skip past it. It is one of the most legally consequential choices you will make about a room, and you usually make it in the first five minutes, before a single document is uploaded.

Point 2: Location matters because it decides who can reach your data

Location determines jurisdiction. Jurisdiction determines who can lawfully read, demand, or restrict your files. Three consequences flow straight from the hosting region.

  • Local data-protection law applies. It can dictate how personal data is handled and whether it may leave the country at all.
  • Local courts and agencies can compel disclosure. They can order the provider to hand over data stored on their soil.
  • Your own promises may require a region. Contracts and regulators can demand a specific location, and breaching that can derail a deal or trigger a fine.
137
Countries with data-protection legislation (UNCTAD)
79%
Share of countries with such laws in force
€20M
Ceiling for the most serious GDPR fines

Why 137 is the number that changed everything

That first figure is the whole reason residency moved from a niche concern to a standard diligence checkbox. According to UNCTAD, 137 of the world’s 194 countries had adopted data-protection and privacy legislation as of its latest count.

A decade ago you could treat “the cloud” as one borderless place. That era is over.

Move a folder of employee records or customer contracts from one region to another today, and you can change the legal rules that govern it. That is precisely the kind of exposure a data room is meant to contain, not create.

The fine is bigger than €20 million

The €20 million ceiling in the panel is only half the GDPR headline. The regulation caps its most serious fines at the greater of €20 million or 4% of worldwide annual turnover.

For a large group, the real exposure scales with revenue. The absolute figure is the floor of the ceiling, not the whole of it.

Flow showing how a data room's hosting region sets its residency, which fixes the governing law and then who can compel access, with a note that the US CLOUD Act follows a US-owned provider anywhere

The diagram above is the whole article in one line. Region sets residency, residency fixes the law, the law decides who can compel access, and the CLOUD Act quietly follows a US-owned provider wherever the servers happen to be. Encryption is a separate layer; for how it fits, see what makes a data room secure.

Point 3: Residency, sovereignty, and localization are three different words

Procurement conversations mix these three up constantly, and the confusion is expensive. They are not synonyms.

Data residency, sovereignty and localization compared

ConceptWhat it meansWho decides itPractical effect on a deal
Data residencyThe physical country where files are stored and processedYou, via the provider's region settingDetermines which legal regime applies by default
Data sovereigntyData is subject to the laws of the country it sits inThe government of the hosting countryLocal courts and agencies can assert access rights
Data localizationA legal mandate to keep specified data inside national bordersNational law (for example finance or health data rules)Removes your freedom to choose a foreign region
Localization requirements are sector- and country-specific; confirm whether any apply to your data before selecting a region.

Residency is a choice

Residency is the one you control. You pick a region, the files sit there. It is the input.

Sovereignty is the consequence

Sovereignty is what the law does with your choice. The country hosting the data asserts authority over it, so choosing a region also chooses which government’s courts can reach your files.

Localization removes the choice

Localization is stricter still. It is a legal mandate that certain data must stay inside national borders and may not leave at all. Where it applies, the region drop-down is decided for you.

Why the vocabulary is not academic

You might pick EU residency for convenience, then learn that sovereignty gives an EU regulator a say. Or that a localization rule in a target market forbids consolidating records in your home region at all.

Getting the words right is the first step to asking a provider the right questions. It is also what lets you read a data processing agreement without glossing over the clause that actually binds the location.

Point 4: A handful of laws draw the boundaries

Several overlapping regimes set the limits. Which ones bite depends on the kind of data and the countries involved.

Data-residency regimes VDR users meet most often

RegimeWhat it governsEffect on VDR hosting
EU GDPRPersonal data of people in the EU/EEAStorage outside the EEA needs a valid transfer mechanism
UK GDPR / Data Protection ActPersonal data of people in the UKSimilar transfer rules; UK-region hosting often requested
US CLOUD ActUS-based providers, wherever data is storedA US provider can be compelled to produce data held abroad
Sector localization lawsHealth, financial or government data in some countriesMay legally require in-country storage, no foreign region
National privacy statutesPersonal data in 130-plus jurisdictionsRegion choice and processing terms must match local rules
This is orientation, not legal advice. Confirm the specific obligations for your data and jurisdictions with qualified counsel.

The GDPR conditions, it does not ban

The most influential regime globally is the EU’s General Data Protection Regulation. It restricts moving personal data out of the European Economic Area unless specific safeguards are in place.

Read that carefully. It conditions the transfer; it does not forbid it. That is a very different thing from a flat ban.

UK GDPR runs a close parallel

After Brexit the UK kept an equivalent regime under the Data Protection Act. Transfer rules are similar, and UK counterparties frequently ask for UK-region hosting as a matter of course.

US law can follow the provider, not the server

This is the counterintuitive one. US legal reach can attach to a US-headquartered provider even when the servers are in Europe. Point 6 unpacks it.

Sector rules can force local storage

Some health, financial, and government data carries a localization mandate in specific countries. Where one applies, no foreign region is lawful, and it overrides your convenience.

National statutes keep multiplying

Beyond the marquee regimes sits a growing list of national privacy laws across 130-plus jurisdictions. Region choice and processing terms have to line up with each one that touches your data.

If your files contain regulated personal data, read our companion guide on GDPR and virtual data rooms alongside this one. Residency and lawful processing are two halves of the same compliance question.

Point 5: A US-hosted room can hold EU data, but not by default

Often the answer is yes. It is a compliance question, not a preference, and getting it wrong carries real risk.

Under the GDPR, transferring EU personal data outside the EEA requires a lawful transfer mechanism. You will meet two of them.

  • An adequacy decision. The European Commission has ruled a country’s protections equivalent.
  • Standard Contractual Clauses. Contractual safeguards the provider signs to cover the transfer.

Since the Court of Justice invalidated the earlier Privacy Shield framework in the 2020 Schrems II ruling, businesses have leaned heavily on Standard Contractual Clauses backed by a case-by-case transfer risk assessment.

Even where Standard Contractual Clauses are used, controllers must verify, on a case-by-case basis, whether the law of the destination country ensures adequate protection, and add supplementary measures where it does not. That principle, set out by the Court of Justice in Schrems II and echoed in EDPB guidance, is why a signature on the clauses is a starting point, not the finish line.

The cleaner route is to keep the data in the EU

The simplest and increasingly common move is to sidestep the transfer question entirely. Choose an EU data centre, and the personal data never leaves the EEA.

When a deal involves European employee or customer records, that is usually the path of least resistance. It is not free of trade-offs, though, so weigh them honestly before committing.

Keeping EU personal data in an EU region: the trade-off

Pros

  • The international-transfer rules under the GDPR fall away entirely, removing the biggest compliance hurdle
  • No dependence on Standard Contractual Clauses or a per-transfer risk assessment for the personal data
  • Reassures European counterparties and their counsel, so residency never surfaces as a late objection
  • Latency for European reviewers is typically lower when the data centre is nearby

Cons

  • An EU region does not, by itself, settle CLOUD Act exposure if the provider is US-owned
  • Some providers gate specific regions to higher plans, so the choice can carry a cost
  • A multi-jurisdiction group may still need more than one region, adding administrative overhead
  • You still owe lawful processing, a proper agreement and security controls; region is one piece

Point 6: The CLOUD Act is why European buyers ask who owns the provider

The US CLOUD Act is a 2018 law. It lets US authorities compel a US-based service provider to produce data in its control, wherever in the world that data physically sits.

Sit with the implication for a second. Choosing a European data centre does not, on its own, put your files beyond US legal process if the provider itself is a US company.

Sovereignty attaches to the provider’s nationality, not only to the server’s location. The pin on the map is not the whole answer.

Why sophisticated counterparties ask a second question

This is why experienced European counterparties, and government-adjacent deals in particular, ask not just “where is the data” but “who ultimately controls the provider”.

For most commercial transactions the residual risk is small and well managed by a certified provider’s audited controls. You can read the US Department of Justice’s own framing in its CLOUD Act resources.

The mitigations that exist for the sensitive cases

For unusually sensitive or sovereignty-critical engagements, the levers are real.

  • Choose a provider incorporated in your own jurisdiction, or one offering a genuinely EU-operated sovereign-cloud option.
  • Hold your own keys. Customer-managed encryption keys or zero-knowledge encryption mean even a compelled provider cannot decrypt the files.

The question to bring into procurement is ownership and control, not just the location of the servers.

Point 7: Getting residency wrong is a quiet failure, not a loud one

The failure mode is rarely a dramatic breach. It is a mismatch that surfaces at the worst possible moment.

It plays out in one of three ways, and each is dearer to fix mid-deal than to prevent at setup.

The diligence stall

The buyer’s counsel discovers that European personal data has been sitting on a US-controlled server without a documented transfer mechanism. The process pauses while the parties paper the gap or re-host the room.

The regulatory exposure

An authority takes the view that a transfer lacked a lawful basis. Now you are explaining yourself to a regulator instead of closing a deal.

The broken promise

You told a counterparty the data would stay in-region, and it did not. That is a trust problem as much as a legal one, and trust is hard to re-paper.

The part teams always underestimate: re-hosting

Moving a live room is heavier than it sounds. It means:

  • migrating every file,
  • rebuilding the folder structure and permission groups,
  • re-inviting every user, and
  • reconciling the audit trail so the record of who saw what survives the move.

None of that is impossible. Doing it while bidders are actively reviewing is disruptive, visible, and avoidable.

The cheap version of this problem is a five-minute region check before upload. The expensive version is a migration under deal pressure. That asymmetry is the entire argument for treating residency as a setup decision, not a running one.

Point 8: Choose the region by working from the strictest law

Do not choose the region for convenience or latency. Choose it by working from the strictest law that touches your data.

The logic runs one way. Identify the most demanding obligation on the files, satisfy that, and everything looser is covered automatically. A five-step pass gets most teams to a defensible choice before any document is uploaded.

How to choose the right VDR hosting region

A practical sequence for pinning a defensible data-residency region before you upload.

Estimated time: 1h

  1. Inventory the sensitive data

    List whether the room will hold EU or UK personal data, regulated health or financial records, or government-related information, since each can carry its own residency rule.

  2. Find the strictest obligation

    Identify the single most demanding requirement across those categories, for example an EU personal-data transfer restriction or a sector localization mandate, and design around it.

  3. Check what the counterparty expects

    Ask the other side early whether they require a specific region or forbid a US-controlled provider, so it does not surface as a late-stage objection.

  4. Select the region in the provider settings

    Choose the matching data-centre region before uploading. Confirm the setting is per-room and that it covers backups and processing, not just primary storage.

  5. Paper the terms

    Get the region, the sub-processors, and the data processing agreement with any Standard Contractual Clauses in writing, so the residency choice is contractual, not just a dashboard toggle.

Do this at the start and it costs an hour. Discover a mismatch during diligence and it costs a migration. The region is a decision to make deliberately, once, at setup.

Point 9: Verify residency claims the way you verify any security claim

Ask for specifics in writing. Refuse to accept a marketing map.

A provider that takes residency seriously can answer every question below without hesitation. Vagueness on any of them is itself a signal.

Ask where backups live, not just the primary store

Residency fails quietly when the live room is in Frankfurt but nightly backups replicate to a US region. Confirm the whole data lifecycle stays in the region you chose.

Get the sub-processor list

Providers rely on infrastructure partners. Make sure none of them move your data outside the intended jurisdiction, and that the data processing agreement names them.

Confirm the region is contractual

A dashboard toggle is not a guarantee. The region should appear in the data processing agreement so it is enforceable, not a default that support can quietly change.

Match it to the certifications

Residency pairs with independent audits. A provider claiming EU hosting should also produce SOC 2 and ISO 27001 evidence, as covered in our guide to what makes a data room secure.

The goal is to convert “we host in Europe” from a slide into a documented, contractual commitment you could rely on in a dispute. The enterprise platforms profiled in our Datasite review and iDeals review are used to answering exactly these questions during a free trial. Pin the answers down before you upload, not after.

Point 10: Most providers now offer a menu of regions

A single fixed location is increasingly the exception. Cross-border deals demand a choice, and established providers have responded.

Common VDR hosting regions and the regime that usually governs them

RegionTypical data-centre locationsPrimary regime to expect
European UnionFrankfurt, Dublin, Amsterdam, ParisEU GDPR, national privacy laws
United KingdomLondonUK GDPR, Data Protection Act
United StatesVirginia, Oregon, OhioState privacy laws, CLOUD Act reach
CanadaToronto, MontrealPIPEDA and provincial statutes
Asia-PacificSydney, Singapore, TokyoLocal privacy and localization rules
Available regions vary by provider and plan; the locations shown are indicative, confirm the exact data-centre options with the provider.

Per-room beats account-wide

Where residency is a genuine deciding factor, region flexibility should sit high on your shortlist alongside security and price.

The more useful arrangement is a region set per room rather than account-wide. Ellty is among the options that let you select a hosting region at the room level. If you run parallel deals in different markets, confirm that granularity explicitly, because an account-wide default forces every room into the same jurisdiction whether the deal needs it or not.

Watch for the edges of the menu

The common set covers the EU, the UK, North America, and increasingly Asia-Pacific. Some vendors add Canada, the Middle East, or dedicated government clouds.

If your deal needs one of the rarer regions, treat its availability as a shortlist filter, not an afterthought.

Point 11: Residency touches pricing and performance only lightly

Residency affects both. It is rarely the main driver of either.

On pricing, expect a modest effect

Choosing a specific or premium region, or requiring a dedicated sovereign-cloud instance, can sit on higher plans. Standard region selection between the EU, UK, and US is commonly available without a dramatic premium.

Treat any figure as indicative and confirm the current terms with the provider, since region-specific and enterprise tiers change often. Our pricing hub tracks how the market packages these tiers.

On performance, the difference is negligible

Hosting data closer to your reviewers can marginally improve load times. Modern providers use content-delivery and rendering techniques that shrink the difference to almost nothing for document review.

Choose your region for legal fit first. Let any small pricing or speed effect be a secondary consideration.

The compliance cost of the wrong region dwarfs the few dollars a month a preferred region might add, and no reviewer has ever abandoned a deal over a fraction of a second in page load.

Point 12: A short residency checklist to keep on hand

Print this. Run it before every new room.

  • Do the files include EU or UK personal data, or regulated health, financial, or government records?
  • What is the single strictest obligation across those categories?
  • Has the counterparty stated a required region or ruled out a US-controlled provider?
  • Does the provider let you set the region per room, before upload?
  • Do backups, replicas, and disaster-recovery copies stay in that same region?
  • Is the region written into the data processing agreement, with sub-processors named?
  • Are SOC 2 and ISO 27001 reports available to back the hosting claim?

If every box is checked before the first document goes in, residency will not be the thing that stalls your diligence.

Frequently asked questions

Is data residency the same as data encryption?

No. Encryption protects the contents of a file so intercepted data is unreadable, while data residency is about the physical country the file is stored in and therefore which laws apply to it. You need both: strong encryption for confidentiality, and the right residency for legal compliance. A perfectly encrypted file in the wrong jurisdiction can still create a compliance problem.

Does choosing an EU data centre satisfy GDPR by itself?

It goes a long way, because keeping EU personal data inside the EEA avoids the international-transfer rules entirely. But GDPR compliance also depends on lawful processing, a proper data processing agreement, and appropriate security controls. Region choice removes one major hurdle; it does not, on its own, make an entire deal GDPR-compliant.

Can I use a US provider for a European deal?

Often yes, provided the provider offers either an EU hosting region or a compliant transfer mechanism such as Standard Contractual Clauses in its data processing agreement. Many teams simply select an EU data centre to keep the personal data in Europe. For sovereignty-sensitive deals, some counterparties also ask about the provider's US ownership because of the CLOUD Act.

What is data sovereignty in plain terms?

Data sovereignty is the principle that your data is subject to the laws of the country where it is stored, and that the country asserts authority over it. Residency is the geographic fact of where the data sits; sovereignty is the legal consequence that flows from it. Choosing a region therefore also chooses which government's courts can reach your files.

Do all data room providers let me choose the region?

Not all, and it is worth checking explicitly. Established providers usually offer a menu of regions and, better still, let you set the region per room rather than only at the account level. Lighter-weight tools may host in a single fixed location, which can be a dealbreaker if your data carries a residency requirement.

Do backups count for data residency?

Yes, everywhere the data lands. Residency is only satisfied if backups, replicas and disaster-recovery copies stay in the same jurisdiction as the primary store. A room hosted in the EU whose backups replicate to a US region has not truly kept the data in Europe, so always confirm the full data lifecycle, not just the main server.

Data residency stays invisible until a counterparty’s counsel raises it, and then it becomes urgent overnight. Staying ahead of it is unglamorous but reliable: know which law is strictest for your files, pick a provider that lets you match the region to it, and get that choice in writing before you upload.

To see how residency options line up against security, features, and pricing across the field, the full comparison and the best data rooms for M&A hub put every provider we score side by side. If your room is heading into a diligence sprint, the best data rooms for due diligence shortlist is the companion view.