What Is Data Residency?
Quick Answer: Data residency is the physical or geographic location where an organisation’s data is stored and processed. It matters because the country where data resides determines which laws, regulators, and government access powers apply to it, making residency a central question in GDPR compliance, vendor selection, and IT security reviews.
Data residency refers to the geographic location where data is physically stored, whether in a specific country, region, or data centre. When a business uploads documents to a cloud service, that data lives on servers somewhere in the world, and the “somewhere” carries legal weight. A contract stored on a server in Frankfurt sits under EU law. The same contract stored on a server in Virginia sits under US law, including legislation like the CLOUD Act that grants US authorities access rights to data held by American providers.
For businesses in regulated industries, data residency is rarely optional. Regulators, auditors, customers, and public sector clients increasingly ask a direct question: where, exactly, is our data?
Data residency vs data sovereignty vs data localisation
People often use these three terms interchangeably, but they describe different things.
Data residency is the factual question: where is the data physically stored? A company adopts a residency requirement when it decides, for policy or contractual reasons, that its data must be stored in a particular geography, for example within the EU.
Data sovereignty is the legal question: whose laws govern the data? Data is subject to the laws of the country where it resides, and often also to the laws of the country where the service provider is headquartered. This is why a European business storing data in an EU data centre operated by a US-headquartered provider still faces sovereignty questions. Residency alone does not settle jurisdiction.
Data localisation is the strictest form: a legal mandate that certain data must stay within a country’s borders and cannot leave. Russia, China, and several other jurisdictions impose localisation laws for specific data categories. Some EU member states apply localisation rules to health records or government data.
In practice, most SMEs care about residency first (can we prove the data stays in the EU?), sovereignty second (which government can compel access?), and localisation only if they operate in a jurisdiction that mandates it.
Why does data residency matter for compliance-focused businesses?
Three reasons dominate: regulation, audits, and customer trust.
Regulation. The GDPR restricts transfers of personal data outside the European Economic Area unless specific safeguards apply. After the Schrems II ruling invalidated the EU-US Privacy Shield in 2020, transfers to US providers became legally fragile, and many European organisations responded by requiring EU data residency as the simplest way to remove transfer risk. GDPR enforcement is not theoretical: cumulative fines passed €4.5 billion by 2024 (CMS GDPR Enforcement Tracker, 2024). Similar residency expectations appear in HIPAA risk assessments, ISO 27001 controls covering supplier relationships, and public procurement requirements across Europe, Australia, and Canada. Meeting them in practice is part of broader GDPR document compliance.
Audits. ISO 27001 and ISO 9001 audits routinely examine where controlled documents, records, and personal data are stored and who can access them. An organisation that cannot answer “where does our data reside?” with a specific region and a supporting contract clause has a gap an auditor will flag. Residency documentation, alongside encryption and access controls, forms part of the evidence pack that makes an audit pass rather than a scramble.
Customer and contractual pressure. B2B buyers increasingly write residency clauses into contracts. A manufacturer supplying a German enterprise, or a professional services firm serving a government client, will often find EU residency listed as a non-negotiable requirement in the security questionnaire. Being unable to satisfy it means losing the deal before the pricing conversation even starts.
How to evaluate data residency in a document management system
When assessing a DMS or any cloud vendor, four questions cut through the marketing language:
- Where are the primary servers located? Ask for the specific region, not “global infrastructure”. A credible vendor names the data centre region in its contract or data processing agreement.
- Where are backups and replicas stored? Data residency claims collapse if backups sit in a different jurisdiction. Confirm that redundancy stays within the committed region.
- Who is the legal entity behind the service? A vendor headquartered outside your jurisdiction may be subject to foreign access laws regardless of server location. European organisations often prefer European-headquartered providers for exactly this reason. Ask for a published list of sub-processors as well, since a subcontractor in another region reopens the same question.
- What deployment options exist if requirements tighten? Some organisations, particularly in healthcare, finance, and government supply chains, eventually need single-tenant or on-premises deployment. A vendor that offers this path avoids a forced migration later.
Folderit answers these questions directly: it is headquartered in Estonia and Germany, hosts customer data on AWS with EU data residency, keeps triple-redundant backups in data centres more than 100 kilometres apart, and offers single-tenant cloud and on-premises deployment for organisations with stricter sovereignty requirements. Our security overview sets out the full control set. That combination lets an IT manager or compliance lead state the data’s location, jurisdiction, and backup geography in one sentence during an audit or security review.
Data residency as a selection criterion, not an afterthought
Residency is one of the few vendor attributes you cannot fix after purchase. Teams can reconfigure access permissions and rebuild workflows, but moving terabytes of controlled documents between jurisdictions is a migration project with legal review attached.
Treating residency as a first-round filter in any DMS evaluation, before comparing features or pricing, saves the far larger cost of discovering a jurisdiction problem during a customer audit or regulatory inquiry. For European SMEs in particular, choosing EU residency from day one removes an entire category of GDPR transfer risk before it exists, and it is worth reading alongside what data compliance means for your business when you set the requirement internally.