GDPR Data Residency Hosting: Essential Guide
Learn why GDPR data residency matters, how Schrems II changed compliance, and how EU hosting eliminates legal transfer complexity. Essential for EU customer data.
- GDPR does not explicitly require data to stay in the EU, but transfers outside the EEA require legal mechanisms (Standard Contractual Clauses, Transfer Impact Assessments) that add complexity and risk.
- The Schrems II ruling in July 2020 undermined US data transfers and made EU hosting the simplest compliance path.
- European data centers eliminate transfer documentation, reduce legal risk, and are often required by B2B customers and regulated sectors.
- Beyond location, you must document your choice in Data Processing Agreements, Records of Processing Activities, encryption, and backup procedures.
- Managed platforms like Ship handle much of the residency compliance automatically; DIY infrastructure requires more careful configuration and verification.
GDPR data residency means your personal data storage location matters legally. It's not just about physical servers; it's about compliance with EU regulations that impose real penalties for violations. The location you choose affects your legal obligations, your customers' trust, and whether regulators treat you as someone taking compliance seriously.
What is GDPR Data Residency?
GDPR data residency is the requirement or commitment to store personal data in a specific geographic region. It differs from data sovereignty (which includes legal jurisdiction and governance rights) and data localization (which is a broader term covering any rule that ties data to a location).
Data residency under GDPR typically refers to keeping personal data within the EU/EEA. Many organizations conflate this with a hard legal requirement, but the regulation itself does not explicitly mandate EU-only storage. What GDPR does mandate is that data processing complies with its principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, integrity, confidentiality, and accountability.
Why does location matter then? Because transferring personal data outside the EU/EEA triggers additional legal obligations. You must establish a legal mechanism (adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules) to justify the transfer. These mechanisms add compliance complexity, legal risk, and ongoing documentation burden. Choosing EU hosting eliminates this entire layer.
For data controllers (companies collecting data) and processors (vendors storing it), the location of your hosting is a core data protection design decision. It appears in your Data Protection Impact Assessment, your Records of Processing Activities (Article 30 documentation), and your customer data processing agreements.
Does GDPR Actually Require Data to Stay in the EU?
No. GDPR does not prohibit transferring personal data outside the EEA. The regulation permits transfers under specific legal gateways.
The first gateway is an "adequacy decision." The European Commission can declare that a non-EU country has an adequate level of data protection. Currently, only six countries or regions hold adequacy decisions: Canada, Israel, Japan, South Korea, the UK, and Argentina. The US does not have a blanket adequacy decision.
When no adequacy decision exists, you can rely on Standard Contractual Clauses (SCCs). These are pre-approved contract templates issued by the European Commission. They bind the data importer (the recipient outside the EU) to protect data according to GDPR standards. You sign them, include them in your processing agreement, and document the transfer.
The third mechanism is Binding Corporate Rules (BCRs), used by multinational organizations to transfer data between internal entities with pre-approved governance.
In theory, all three options are valid. In practice, SCCs became unreliable after the Schrems II ruling in 2020.
The Schrems II Turning Point: Why EU Hosting Became Simpler
On July 16, 2020, the Court of Justice of the European Union (CJEU) invalidated Privacy Shield, an older framework that allowed EU-US data transfers. The ruling concluded that US government surveillance (authorized under laws like FISA) undermined Privacy Shield's protections.
The court did not ban SCCs outright, but it required organizations to perform a "Transfer Impact Assessment" (TIA). This assessment examines whether the laws in the destination country allow government access that conflicts with GDPR's guarantees. If risks are found, you must implement "supplementary measures" (encryption, access controls, restricted access policies) to mitigate them.
For US-based hosting, this meant: you must assess whether US surveillance laws permit government access to your EU customers' data. If yes (which is almost always the case), you must document supplementary measures. This is tedious but not impossible.
The ruling created a watershed moment. Organizations realized that staying within the EU/EEA was simpler: you do not need SCCs, you do not need a TIA, you do not need supplementary measures. A hosting provider in Frankfurt, Amsterdam, or Dublin uses EU infrastructure, EU legal frameworks (GDPR itself), and EU court jurisdiction. Compliance is straightforward.
Why European Data Centers Matter for Your Business
Choosing EU/EEA hosting provides four concrete advantages:
1. Simplified Compliance. No need to navigate SCCs, Transfer Impact Assessments, or supplementary measures. Your legal and compliance teams spend less time on documentation. Your auditors see a cleaner story: data stays in GDPR territory.
2. Reduced Legal Risk. Regulators (like data protection authorities in France, Germany, Austria) view EU hosting as the gold standard. If you are under investigation for a data breach or processing violation, your choice to use EU infrastructure is a mitigating factor. It demonstrates that you took data protection seriously from day one.
3. Customer Trust and Competitive Advantage. B2B customers, especially in regulated sectors, often require EU hosting in their contracts. Healthcare providers, financial services, government agencies, and SaaS vendors catering to Europe all mandate this. You cannot sell to them without it.
4. Sector-Specific Legal Requirements. Some regulations impose stricter rules than GDPR. Healthcare (under HIPAA equivalents in individual EU countries), finance (under PSD2 and other directives), and government contracts often require storage in specific EU member states. If your data is already EU-based, you have flexibility. If it is in the US, you are locked out.
These four factors compound. Choosing EU hosting is not just a legal box-check; it is a business decision that opens markets, reduces risk, and simplifies operations.
Choosing Hosting: Infrastructure vs. Managed Platforms
When selecting where to run your application, you face two broad paths: infrastructure providers (like Hetzner and OVH) and managed platforms.
Infrastructure providers rent you servers or cloud capacity in EU data centers. Hetzner and OVH both operate data centers across Europe. You deploy your application, manage your own backups, encryption, and access controls. This path offers flexibility and cost efficiency but requires your team to handle security and compliance configuration. You are responsible for documenting that backups stay in the EU, that disaster recovery replicates within the EU, and that all subprocessors (vendors your hosting provider relies on) are also EU-based.
Managed platforms handle much of this for you. They run applications in EU data centers, provide built-in encryption, handle backups, and document compliance. They often publish compliance certifications (ISO 27001, SOC 2) and provide Data Processing Agreements. The tradeoff: less flexibility, higher cost per compute unit, and a dependency on the platform's architecture choices.
A critical gap many teams miss: disaster recovery and backups must also be residency-compliant. If you run on a Hetzner server in Frankfurt but back up to AWS S3 in Virginia, your backup data left the EU. This violates GDPR. Your hosting contract must specify where backups are stored. Managed platforms typically handle this transparently: they back up within EU infrastructure by default. DIY infrastructure requires you to verify and configure it yourself.
For a 10-50 person company, a managed platform often makes more sense: lower compliance risk, less operational overhead, and a vendor who can produce documentation for audits. For larger organizations or specialized workloads, DIY infrastructure offers cost and flexibility advantages, but demands more rigor in your data residency documentation.
Key Compliance Requirements Beyond Location
Choosing EU hosting solves the "where" question, but you still must address "how." GDPR requires documentation and governance across five areas:
Data Processing Agreements (DPAs). If your hosting provider processes personal data on your behalf, you must execute a written DPA with them. The DPA must specify: the types of data processed, the duration, the nature of processing, the purpose, and the categories of personal data subjects. It must also include standard clauses on subprocessor management, data subject rights, assistance with audits, and liability. Most hosting providers provide a template DPA. Review it; do not skip this.
Records of Processing Activities (Article 30). You must document what personal data you process, where you store it, who accesses it, how long you keep it, and your legal basis for processing. This is your GDPR record-keeping. Include your hosting provider's location, data center details, and backup locations. When regulators audit you, they ask to see this record. A clear, detailed record demonstrates accountability.
Encryption and Access Controls. GDPR requires you to implement technical and organizational measures appropriate to the risk. This includes encryption in transit (TLS for data sent to your server) and encryption at rest (data stored on disk). It also includes access controls: only authorized personnel should be able to decrypt or access personal data. Document what encryption you use, who holds encryption keys, and who can access data. Managed platforms provide encryption by default. DIY infrastructure requires you to configure and document it.
Breach Notification and Subprocessor Transparency. If personal data is breached (unauthorized access), you must notify regulators within 72 hours. GDPR requires you to notify data subjects unless there is low risk of harm. Document your breach response process: detection, triage, notification, remediation. You must also maintain a list of subprocessors: vendors you use who process data on your behalf (e.g., a backup vendor, a monitoring service, a payment processor that touches data). When you add or change subprocessors, you must notify customers who have the right to object.
Beyond these four, maintain audit logs. Record who accessed personal data, when, and why. Store these logs for a reasonable retention period (typically 1-2 years). They are the first thing regulators review in an investigation.
Data Residency Requirements by Region
While GDPR is the global standard most familiar to US founders, data residency is not unique to the EU.
EU/EEA. Established: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland. GDPR applies; personal data should stay within this region unless a legal transfer mechanism is in place.
UK. Post-Brexit, the UK held an adequacy decision (as of July 2023) allowing data transfers to the UK from the EU. However, this decision is subject to review and is not permanent. Many organizations treat UK data separately and do not rely on UK hosting for EU-bound personal data.
US. No blanket adequacy. The EU-US Data Privacy Framework, adopted in July 2023, allows certified US companies (primarily cloud providers) to receive EU personal data if they adhere to specific protections and consent to US government oversight within defined limits. This is the current legal framework for AWS, Microsoft Azure, and Google Cloud. However, organizations can avoid this complexity by using EU regions offered by these providers.
Other Regions. Canada (adequacy), Japan (adequacy), South Korea (adequacy), and Argentina (adequacy) allow EU data transfers. China, India, Russia, Saudi Arabia, and most other countries do not have adequacy decisions. Transferring data to these regions requires SCCs and Transfer Impact Assessments.
For a company selling into Europe, the simplest rule is: store EU customer data in the EU. Avoid the complexity of SCCs and TIAs. If you must serve a global market and need to centralize backups or analytics, use a managed platform that offers EU data residency as a compliance-first option.
Documenting Your Residency Choice
Once you select a hosting provider, document the choice and verify compliance.
Step 1: Audit Your Provider's Infrastructure. Ask your hosting provider: In which countries are data centers located? Which one will my data be stored in? Are backups kept in the same country? Can they provide a map or list? Most providers have this documented on their website or in a trust center.
Step 2: Verify Subprocessors. Your hosting provider likely uses subprocessors (monitoring vendors, backup vendors, DNS providers). Ask for a list. Verify that subprocessors do not move data outside the EU unless a legal basis exists.
Step 3: Review the Data Processing Agreement. Ensure the DPA specifies: (a) the hosting provider will process data only in the EU, (b) backups and disaster recovery stay in the EU, (c) the provider will assist you in meeting data subject rights requests, (d) the provider will notify you of data breaches, (e) the provider will allow audits.
Step 4: Document in Your Records of Processing Activities (ROPA). Include: hosting provider name, EU data center location(s), encryption methods, access control policies, backup and retention details. Include the date you verified this information. Update annually or whenever your infrastructure changes.
Step 5: Communicate with Customers. If you process personal data on behalf of customers (you are a processor), include your hosting and data residency details in your DPA. Many customers will ask during vendor evaluation; having clear documentation accelerates sales.
This documentation burden is manageable. A small organization with one hosting provider and one data center location can document this in a few hours. A large organization with multiple platforms and regions may need to maintain a compliance register, but the information itself is straightforward.
Frequently Asked Questions
Can GDPR data be stored in the US? Yes, if you have a legal mechanism in place. This includes: (1) certification under the EU-US Data Privacy Framework (for certified US cloud providers), (2) Standard Contractual Clauses with a Transfer Impact Assessment showing supplementary measures to mitigate US surveillance laws, or (3) anonymization (if the data is truly anonymized, GDPR does not apply). However, most organizations find it simpler to store EU customer data in the EU.
Does it matter where geographic location your data is stored? Under GDPR, yes, it matters significantly. The location determines whether your data transfer triggers additional legal obligations. EU storage means no transfer, no SCCs, no TIA. Non-EU storage requires legal mechanisms and ongoing documentation. For customer trust and regulatory certainty, location is one of the first questions auditors ask.
Does GDPR allow data sharing? Yes, but with restrictions. You can share data with third parties if you have a legal basis (consent, contract, legal obligation, vital interests, etc.), and you must inform data subjects about the sharing. If the third party is a processor (acts on your instructions), you need a Data Processing Agreement. If they are a controller (independent decision-maker), you need a lawful basis and transparency notice. Sharing is allowed; uncontrolled sharing is not.
Is there an equivalent of GDPR in the US? No federal equivalent. The US uses a sector-based approach: HIPAA (healthcare), CCPA/CPRA (consumer privacy in California), GLBA (financial services), FTC Act (general privacy rules). There is no single regulation like GDPR. However, many US states are adopting privacy laws modeled on CCPA, which are often stricter than GDPR in some areas.
Is GDPR compliance mandatory in the USA? GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization is based. A US company serving European customers must comply. If you have even one EU customer and you process their personal data (email, name, payment info), GDPR applies.
Is GDPR more strict than HIPAA? They are different. GDPR is broader (covers all personal data), but HIPAA is sector-specific (healthcare only) and imposes stricter technical standards (encryption, access logs, breach notification within 60 days vs. GDPR's 72 hours for regulators). If you operate in healthcare, you must comply with both. GDPR does not replace HIPAA; it adds a second layer of obligations for EU patient data.
The Bottom Line
GDPR data residency is not a myth or a burden created by regulators seeking complexity. It is a direct consequence of EU legal frameworks protecting citizen privacy. Storing personal data in the EU dramatically simplifies your compliance because you avoid the complexity of legal transfer mechanisms, Transfer Impact Assessments, and supplementary measures.
Choosing EU hosting is a business decision, not just a legal one. It opens access to European customers who require it, reduces audit risk, and demonstrates that you take data protection seriously. The cost of EU hosting has converged with US hosting; the compliance cost of avoiding EU hosting has risen.
Start by selecting a hosting provider with transparent EU data residency, execute a clear Data Processing Agreement, document your choice in your Records of Processing Activities, and verify your backups and disaster recovery plans stay within the EU. Then move on to running your business. Ship's managed PaaS offering includes GDPR-compliant infrastructure and documentation; see our /hosting/ship/gdpr-compliant-paas for a deeper dive into platform-based compliance.