← all glossary terms

GDPR data residency

Keeping personal data on infrastructure inside a specific jurisdiction (typically the EU) to satisfy regulatory or contractual constraints.

Data residency is the requirement that personal data about a defined population be stored and processed only within a specific legal jurisdiction. Under GDPR (Regulation (EU) 2016/679), transfers of EU residents' personal data to "third countries" require an adequacy decision, Standard Contractual Clauses, or another approved transfer mechanism. The Schrems II ruling (2020) struck down the EU–US Privacy Shield, and many EU customers now require their suppliers to keep PII on EU-hosted infrastructure end-to-end. "EU data residency" on a vendor pricing page usually means: the database, the backups, and any sub-processor pipeline live in the EU.

In a self-hosting context

Self-hosting is the most direct way to guarantee data residency: you pick the data center. The VPS providers compared comparison flags which providers offer EU-only regions (Hetzner is Frankfurt and Helsinki by default; OVH France; Scaleway Paris and Amsterdam). Replacing a US-hosted SaaS like Slack, Notion, or Datadog with a self-hosted Mattermost, Nextcloud, or open observability stack on an EU VPS is a defensible end-to-end residency story.

All 30 terms