SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO
German MarketFeb 8, 20269 min read

EU Data Residency: What the Law Requires and When It Helps

MW
Malte Wagenbach

Founder & CEO, Matproof

"We need EU data residency" is one of the most common lines in a vendor questionnaire from a European bank or insurer. It is also one of the most misunderstood. No EU regulation obliges a financial institution to keep all of its data inside the European Union. What the law does require is more specific: GDPR sets rules for transferring personal data out of the EU, and DORA requires you to know, document and contractually fix where your ICT providers process and store data.

This article separates the legal duties from the business choice. It explains what GDPR, DORA and NIS2 actually say, where EU hosting makes your life easier, and what questions to ask any compliance tool before you put your audit evidence into it.

Residency, localisation, sovereignty: three different things

These terms get mixed up, so it helps to define them first.

  • Data residency is where data is stored. "EU data residency" usually means the provider stores your data in data centres inside the EU.
  • Data localisation is a legal requirement that data must stay in a country or region. EU law has very few of these for the private sector. GDPR and DORA contain none.
  • Data sovereignty is about which legal system can reach the data. A server in Frankfurt run by a company that must obey a foreign authority is resident in the EU, but not fully sovereign.

Most vendor claims are about residency. Most real risks are about transfers and access. Keep that difference in mind for the rest of this article.

What GDPR actually requires

Not sure which regulation applies to you?

Find my frameworks in 60s

GDPR does not say where personal data must be stored. Chapter V (Articles 44 to 50) says when personal data may be transferred to a country outside the European Economic Area. A transfer is lawful if one of these applies:

  1. An adequacy decision (Article 45). The European Commission has decided that the country offers an essentially equivalent level of protection. Since July 2023 this includes US organisations certified under the EU-US Data Privacy Framework.
  2. Appropriate safeguards (Article 46), most often the Standard Contractual Clauses (SCCs), or Binding Corporate Rules (Article 47) inside a corporate group.
  3. A derogation (Article 49) for specific situations, such as explicit consent. These are narrow and not meant for routine transfers.

Since the Schrems II judgment of the Court of Justice (C-311/18, July 2020), which struck down the old Privacy Shield, SCCs alone are not always enough. You need to assess whether the law of the destination country undermines them, and add supplementary measures where it does. This is the transfer impact assessment.

Breaking the transfer rules is expensive. Under Article 83(5)(c), fines can reach EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher. But note what the fine is for: an unlawful transfer, not the mere fact that a server sits outside the EU.

What DORA actually requires

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025. It contains no data-residency rule. It does contain several duties about data location:

  • Article 30(2)(b): every contract for ICT services must state the regions or countries where the services are provided and where data is processed, including the storage location. The provider must tell you in advance if it plans to change them.
  • Article 28(3): you must keep a register of information on all contractual arrangements with ICT third-party service providers. Supervisors use it to see where your critical functions depend on whom, and where.
  • Article 29: before you sign, you assess concentration risk, including long subcontracting chains and providers established in third countries.
  • Article 28(8): for services that support critical or important functions, you need an exit strategy.
  • Article 31(12): you may only use an ICT provider that the European Supervisory Authorities designate as critical, and that is established outside the EU, if it sets up a subsidiary in the Union within 12 months. This is about the provider's legal establishment, not about where your data is stored.

National competent authorities can impose administrative penalties and remedial measures for breaches (Article 50). In practice, the common finding is not "data stored in the wrong place" but "you did not know or document where it is stored, and you did not assess the risk".

What NIS2 requires

NIS2 (Directive (EU) 2022/2555) asks essential and important entities to manage supply chain security as part of their cybersecurity risk measures (Article 21). It does not require EU storage either.

So why do so many buyers ask for EU hosting?

Because it removes work and risk, even if no law forces it. For a compliance tool in particular, EU hosting means:

  • Fewer transfers to assess. If persistent data stays in the EU, there is less to cover with SCCs and transfer impact assessments.
  • Simpler DORA documentation. The location entry in your contract and register is short and stable.
  • Less exposure to foreign access laws. Data held by a US provider can, under the US CLOUD Act, be subject to US disclosure orders even when stored in Europe. An EU provider on EU infrastructure reduces that exposure.
  • Easier supervisory and customer conversations. Many of your own customers, and some public-sector contracts, ask for EU hosting in their procurement terms. That is a contractual requirement, not a statutory one, but it is just as binding once signed.

Compliance evidence is sensitive. It describes your control weaknesses, your incidents and your vendors. Where it is stored and who can reach it deserves the same scrutiny you apply to customer data.

Questions to ask any compliance tool

Do not stop at "Do you offer EU data residency?". Ask these instead:

  1. Where is persistent customer data stored, including backups? Ask for regions, not marketing words.
  2. Which subprocessors handle our data, and where? A serious vendor publishes the full list.
  3. Does any processing happen outside the EU? AI features often use large language model providers. Find out who they are, where they run, and on which transfer basis (adequacy, SCCs).
  4. Can we keep AI processing in the EU if we need to?
  5. What will you put in the contract? Check that the answers above appear in the agreement, as DORA Article 30(2)(b) requires, together with a change-notification clause.
  6. How do we exit? Export formats, deletion, and timelines for the exit strategy DORA expects.

Common mistakes

  1. Treating residency as the whole answer. A tool can store data in the EU and still send it elsewhere for processing. Ask about processing, not only storage.
  2. Forgetting subcontractors. Your provider's providers count. DORA's concentration-risk assessment explicitly covers subcontracting chains.
  3. Relying on SCCs without an assessment. After Schrems II, you need to document why the clauses work for that destination.
  4. Leaving locations out of the contract. Under DORA this is a compliance gap in itself, even if the vendor's website says the right things.
  5. Skipping backups and disaster recovery. Backup regions are data locations too.

Where Matproof stands

Matproof is a compliance automation platform for EU financial services. To be concrete about our own setup:

  • Persistent customer data, including your audit evidence, is hosted in Germany.
  • Our standard AI features use OpenAI and Anthropic, which are US providers, under Standard Contractual Clauses. Regulated customers can switch on an EU option that keeps AI processing in the EU.
  • The full list of subprocessors, with locations, is published on our privacy page.

We would rather you check this than take a slogan on trust.

Getting started

  1. Map your data flows for your compliance and GRC tooling: what data goes where, stored and processed.
  2. Update your register of information with the locations you find, and flag gaps.
  3. Check every ICT contract for location clauses and change notification.
  4. Review transfer bases for any processing outside the EEA, and run transfer impact assessments where SCCs are used.
  5. Decide where EU hosting is a requirement for you, based on your customers' contracts and your risk appetite, and make it a selection criterion rather than an assumption.

Frequently asked questions

Q: Does GDPR require us to store personal data in the EU?
No. GDPR regulates transfers of personal data to countries outside the EEA (Chapter V). Transfers are lawful with an adequacy decision, appropriate safeguards such as Standard Contractual Clauses, or Binding Corporate Rules.

Q: Does DORA require EU data residency?
No. DORA requires ICT contracts to state where services are provided and where data is processed and stored (Article 30(2)(b)), a register of information (Article 28(3)), and an assessment of third-country and concentration risk (Article 29).

Q: Is the EU-US Data Privacy Framework enough for US tools?
It is a valid transfer basis since July 2023, but only for US organisations certified under it. Check the certification, and keep in mind that earlier frameworks (Safe Harbor, Privacy Shield) were struck down by the Court of Justice.

Q: What are the penalties?
Unlawful transfers of personal data can be fined up to EUR 20 million or 4 percent of worldwide annual turnover under GDPR Article 83(5). Under DORA, national authorities set administrative penalties and remedial measures for failures in ICT third-party risk management (Article 50).

Q: Is EU hosting still worth it?
Often yes. It reduces transfer assessments, simplifies DORA documentation and meets the procurement terms many customers set. Treat it as a deliberate choice backed by your risk assessment, not as a legal must-have.

Key takeaways

  • No EU law requires financial institutions to keep all data in the EU.
  • GDPR regulates transfers of personal data out of the EEA. DORA requires documented, contractually fixed data locations and a risk assessment.
  • EU hosting is a strong choice for sensitive data such as compliance evidence, because it reduces transfers, foreign access risk and documentation effort.
  • Ask vendors about storage, processing, subprocessors and AI, and get the answers into the contract.

For a free assessment of your compliance setup, visit https://matproof.com/contact.

Related reading


Ready to act on this? Matproof runs continuous AI penetration testing and compliance monitoring. Book a demo.

EU data residencydata sovereigntyGDPR international transfersDORA Article 30EU cloud compliance

Not sure which framework applies?

Answer 5 questions, get a tailored shortlist of the regulations you need to comply with — in 60 seconds.

Find my frameworks

Ready to simplify compliance?

Get audit-ready in weeks, not months. See Matproof in action.

Request a demo